Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spy-emergency
Spy-emergency spy Emergency |
|
| Vendors & Products |
Spy-emergency
Spy-emergency spy Emergency |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges. | |
| Title | Spy Emergency build 23.0.205 Unquoted Service Path Privilege Escalation | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-04T13:50:59.759Z
Updated: 2026-04-06T18:02:54.460Z
Reserved: 2026-04-04T13:38:36.937Z
Link: CVE-2016-20056
Updated: 2026-04-06T17:59:59.610Z
Status : Awaiting Analysis
Published: 2026-04-04T14:16:18.057
Modified: 2026-04-07T13:20:55.200
Link: CVE-2016-20056
No data.