---
id: CVE-2016-20093
title: >-
  Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path
  vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively,
  allowing local users to execute arbitrary code with SYSTEM privileges
summary: >-
  Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path
  vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively,
  allowing local users to execute arbitrary code with SYSTEM privileges.
  Attackers c…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
published: '2026-06-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T09:10:00.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-20093'
references:
  - url: 'http://www.wisecleaner.com'
    label: disclosure@vulncheck.com
  - url: 'http://www.wisecleaner.com/wise-disk-cleaner.html'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/40417'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wise-care-365-and-wise-disk-cleaner-unquoted-service-path-privilege-escalation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00175
epssPercentile: 0.06285
ingestedAt: '2026-09-29T09:30:49.073Z'
---

## Overview

Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that execute during service startup or system reboot with elevated privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
