---
id: CVE-2016-20091
title: >-
  Windows Firewall Control 4.8.6.0 contains an unquoted service path
  vulnerability that allows local attackers to escalate privileges by inserting
  malicious executables in the service path
summary: >-
  Windows Firewall Control 4.8.6.0 contains an unquoted service path
  vulnerability that allows local attackers to escalate privileges by inserting
  malicious executables in the service path. Attackers can place executable
  files in unquoted …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
published: '2026-06-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T09:10:00.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-20091'
references:
  - url: 'http://www.binisoft.org'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/40443'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/windows-firewall-control-unquoted-service-path-privilege-escalation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00165
epssPercentile: 0.05035
ingestedAt: '2026-09-29T09:30:49.072Z'
---

## Overview

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
