CVE-2016-20093
Received
Received - Intake
Wise Care 365 Unquoted Service Path Privilege Escalation
Publication date: 2026-06-19
Last updated on: 2026-06-19
Assigner: VulnCheck
Description
Description
Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that execute during service startup or system reboot with elevated privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wise_care | wise_care_365 | 4.27 |
| wise_disk_cleaner | wise_disk_cleaner | 9.29 |
| wisecleaner | wise_care_365 | 4.27 |
| wisecleaner | wise_disk_cleaner | 9.29 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-428 | The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. |