---
id: CVE-2016-20092
title: >-
  NetDrive 2.6.12 contains an unquoted service path vulnerability in the
  Netdrive2_Service_Netdrive2 service that allows local users to execute
  arbitrary code with SYSTEM privileges
summary: >-
  NetDrive 2.6.12 contains an unquoted service path vulnerability in the
  Netdrive2_Service_Netdrive2 service that allows local users to execute
  arbitrary code with SYSTEM privileges. Attackers can insert malicious
  executables in the system…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
published: '2026-06-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T09:10:00.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-20092'
references:
  - url: 'http://www.netdrive.net/'
    label: disclosure@vulncheck.com
  - url: 'http://www.netdrive.net/download'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/40422'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/netdrive-unquoted-service-path-elevation-of-privilege
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00175
epssPercentile: 0.06286
ingestedAt: '2026-09-29T09:30:49.073Z'
---

## Overview

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
