PT-2026-30356 · Iobit · Malware Fighter

Published

2026-04-04

·

Updated

2026-04-27

·

CVE-2016-20059

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IObit Malware Fighter version 4.3.1
Description An unquoted service path issue exists in the 'IMFservice' and 'LiveUpdateSvc' services. This allows local attackers to escalate privileges by inserting a malicious executable file into the unquoted service path. When the service restarts or the system reboots, the malicious code is executed with LocalSystem privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Weakness Enumeration

Related Identifiers

CVE-2016-20059

Affected Products

Malware Fighter