← Vulnerability feed

Vulnerability record · CVE-2016-20059 · published 4 April 2026

CVE-2016-20059: Iobit malware fighter unquoted search path vulnerability

Iobit · Malware Fighter

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

8.5 CVSS 4.0 High EPSS 0.18% · top 93.5% CWE-428 · Unquoted search path
8.5CVSS 4.0 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
21 Jul 2026Last modified by NVD

Description

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-20059 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-1646Iobit malware fighter stack-based buffer overflow vulnerabilityA vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x…EPSS 0.37%7.8CVE-2020-23864Iobit malware fighter vulnerabilityAn issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the Windo…EPSS 0.51%7.8CVE-2018-19084Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E05C with a size larger …EPSS 0.60%7.8CVE-2018-19085Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E048 with a size larger …EPSS 0.60%7.8CVE-2018-19086Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E040 with a size larger …EPSS 0.60%7.8CVE-2018-19087Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E044 with a size larger …EPSS 0.60%7.8CVE-2018-18714Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This c…EPSS 0.87%7.8CVE-2018-18026Iobit malware fighter out-of-bounds write vulnerabilityIMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use …EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2016-20059), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.