CVE-2016-20091Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-428

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-22: 2Technical Details · 2026-06-22: 206-22
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2016-20091 Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables… https://www.cve.org/CVERecord?id=CVE-2016-20091 ----- Traducción: CVE-2016-20091 Win… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2016‑20091, describing an unquoted service path issue in Windows Firewall Control that enables local privilege escalation.

    0000023
    88 followersView on X
  • CVE@CVEnew
    General

    CVE-2016-20091 Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables… https://www.cve.org/CVERecord?id=CVE-2016-20091

    Post summary

    The post provides a concise technical description of CVE-2016-20091—a Windows Firewall Control unquoted service path vulnerability that can lead to local privilege escalation—but it offers no PoC, exploit, patch, or evidence of active exploitation.

    00000727
    57.7K followersView on X

Explore more