CVE-2016-20087Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service binary path. Attackers can insert malicious executables in the system root path that execute with SYSTEM privileges during service startup or system reboot.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-428

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-22: 2Technical Details · 2026-06-22: 206-22
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2016-20087 Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the se… https://www.cve.org/CVERecord?id=CVE-2016-20087 ----- Traducción: CVE-2016-20087 For… http://infoflow.cloud`

    Post summary

    The tweet only gives a brief technical description of CVE‑2016‑20087 and links to the official CVE record, with no PoC, exploit code, patch information, or active exploitation evidence.

    0000022
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2016-20087 Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the se… https://www.cve.org/CVERecord?id=CVE-2016-20087

    Post summary

    The tweet references CVE-2016-20087 and describes an unquoted service path flaw that permits local users to run code with elevated privileges, but it lacks PoC, exploit, or patch information.

    00000686
    57.7K followersView on X

Explore more