NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgate
Netgate netgate Registry Cleaner |
|
| Vendors & Products |
Netgate
Netgate netgate Registry Cleaner |
Mon, 06 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges. | |
| Title | NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-04T13:51:00.540Z
Updated: 2026-04-06T16:43:10.464Z
Reserved: 2026-04-04T13:39:28.719Z
Link: CVE-2016-20057
Updated: 2026-04-06T16:43:04.768Z
Status : Awaiting Analysis
Published: 2026-04-04T14:16:18.223
Modified: 2026-04-07T13:20:55.200
Link: CVE-2016-20057
No data.