CVE-2016-20089Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be executed with elevated privileges during service startup or system reboot.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-428

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-22: 2Technical Details · 2026-06-22: 206-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2016-20089 Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the servic… https://www.cve.org/CVERecord?id=CVE-2016-20089 ----- Traducción: CVE-2016-20089 Ipe… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2016-20089, describing an unquoted service path flaw that permits local privilege escalation to SYSTEM. It does not mention any PoC, exploit, patch, or active exploitation.

    0000021
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2016-20089 Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the servic… https://www.cve.org/CVERecord?id=CVE-2016-20089

    Post summary

    The post announces that CVE‑2016‑20089 in Iperius Remote 1.7.0 allows local users to execute code as SYSTEM via an unquoted service path vulnerability, with no PoC, exploit, or patch details provided.

    00000701
    57.7K followersView on X

Explore more