# CVE-2016-20093

## Summary

- **CVE ID:** CVE-2016-20093
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-428
- **Published:** Jun 19, 2026
- **Last Modified:** Jul 15, 2026

## Description

Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that execute during service startup or system reboot with elevated privileges.

## Affected Products

- Wise — Wisecleaner (9.29)
- Wisecleaner — Wise Care 365 (4.27)
- Wisecleaner — Wise Disk Cleaner (9.29)

## References

- [CNA](https://www.exploit-db.com/exploits/40417)
- [CNA](http://www.wisecleaner.com)
- [CNA](http://www.wisecleaner.com/wise-disk-cleaner.html)
- [CNA](https://www.vulncheck.com/advisories/wise-care-365-and-wise-disk-cleaner-unquoted-service-path-privilege-escalation)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._