CVE-2016-20061 identifies an unquoted service path vulnerability (CWE-428) within the ShavProt service of sheed AntiVirus 2.3, which allows local attackers to escalate privileges. Rated 7.8 HIGH, this flaw enables an attacker with low privileges to insert a malicious executable into the unquoted path, achieving LocalSystem code execution upon service restart or system reboot, leading to a complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB, with only minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sheedantivirus | Sheed AntiVirus | 2.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.