IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.
Metrics
Affected Vendors & Products
References
History
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges. | |
| Title | IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation | |
| First Time appeared |
Iobit
Iobit malware Fighter |
|
| Weaknesses | CWE-428 | |
| CPEs | cpe:2.3:a:iobit:malware_fighter:11.0.0.1274:*:*:*:*:*:*:* cpe:2.3:a:iobit:malware_fighter:4.0.3.22:*:*:*:*:*:*:* cpe:2.3:a:iobit:malware_fighter:4.2.02425:*:*:*:*:*:*:* cpe:2.3:a:iobit:malware_fighter:4.3.1:*:*:*:*:*:*:* cpe:2.3:a:iobit:malware_fighter:4.5.03457:*:*:*:*:*:*:* cpe:2.3:a:iobit:malware_fighter:5.5.0:*:*:*:*:*:*:* cpe:2.3:a:iobit:malware_fighter:8.0.2.547:*:*:*:-:*:*:* cpe:2.3:a:iobit:malware_fighter:8.0.2.547:*:*:*:pro:*:*:* cpe:2.3:a:iobit:malware_fighter:9.2:*:*:*:*:*:*:* cpe:2.3:a:iobit:malware_fighter:9.4.0.776:*:*:*:*:*:*:* |
|
| Vendors & Products |
Iobit
Iobit malware Fighter |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-04T13:51:02.758Z
Updated: 2026-04-04T19:59:48.106Z
Reserved: 2026-04-04T13:42:51.909Z
Link: CVE-2016-20059
No data.
Status : Received
Published: 2026-04-04T14:16:18.557
Modified: 2026-04-04T14:16:18.557
Link: CVE-2016-20059
No data.