# CVE-2016-20091

## Summary

- **CVE ID:** CVE-2016-20091
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-428
- **Published:** Jun 19, 2026
- **Last Modified:** Jul 15, 2026

## Description

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

## Affected Products

- Binisoft — Windows Firewall Control (4.8.6.0)

## References

- [CNA](https://www.exploit-db.com/exploits/40443)
- [CNA](http://www.binisoft.org)
- [CNA](https://www.vulncheck.com/advisories/windows-firewall-control-unquoted-service-path-privilege-escalation)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._