---
id: CVE-2016-20056
title: >-
  Spy Emergency build 23.0.205 contains an unquoted service path vulnerability
  in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to
  escalate privileges by inserting malicious executables
summary: >-
  Spy Emergency build 23.0.205 contains an unquoted service path vulnerability
  in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to
  escalate privileges by inserting malicious executables. Attackers can place
  executab…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
published: '2026-04-04'
updated: '2026-07-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-20056'
references:
  - url: 'http://www.spy-emergency.com/'
    label: disclosure@vulncheck.com
  - url: 'http://www.spy-emergency.com/download/download.php?id=1'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/40550'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/spy-emergency-build-unquoted-service-path-privilege-escalation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00155
epssPercentile: 0.04982
ingestedAt: '2026-07-21T16:51:41.014Z'
---

## Overview

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
