Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgate
Netgate netgate Amiti Antivirus |
|
| Vendors & Products |
Netgate
Netgate netgate Amiti Antivirus |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 04 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges. | |
| Title | Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-04T13:51:01.284Z
Updated: 2026-04-06T17:52:16.457Z
Reserved: 2026-04-04T13:41:12.280Z
Link: CVE-2016-20058
Updated: 2026-04-06T17:52:07.396Z
Status : Awaiting Analysis
Published: 2026-04-04T14:16:18.390
Modified: 2026-04-07T13:20:55.200
Link: CVE-2016-20058
No data.