CVE-2016-20061

7.8

Sheed · AntiVirus

Sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service, allowing local attackers to escalate privileges to LocalSystem.

Executive summary

A local privilege escalation vulnerability in Sheed AntiVirus 2.3 allows authenticated attackers to execute arbitrary code with LocalSystem privileges.

Vulnerability

The vulnerability exists due to an unquoted service path in the ShavProt service, which permits a local user with basic access to place a malicious executable in the path and trigger its execution upon service restart or system reboot. This flaw requires local access but does not require administrative privileges to initiate the escalation process.

Business impact

Successful exploitation of this vulnerability results in a complete compromise of the affected host, as the attacker gains LocalSystem privileges. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized data access, persistence within the environment, and the potential for lateral movement across the network.

Remediation

Immediate Action: Update Sheed AntiVirus to the latest available version provided by the vendor, or contact Sheed support to obtain a patch that corrects the service path configuration.

Proactive Monitoring: Monitor system logs for unexpected service restarts or the creation of unauthorized executable files within the C:\Program Files\Sheed AntiVirus directory.

Compensating Controls: Ensure that standard users lack write permissions to the directories used by system services. Implementing strict application whitelisting can also prevent the execution of unauthorized binaries placed in vulnerable paths.

Exploitation status

Public Exploit Available: Yes, a public exploit exists as documented by the researcher on ExploitDB (EDB-ID 40497).

Analyst recommendation

This vulnerability presents a significant risk to endpoint security by enabling full system compromise from a low-privileged account. Organizations should prioritize patching or applying configuration changes to ensure the service path is properly quoted and protected from unauthorized modification.

Sources

Originally found and disclosed by Amir.ght, per the CVE Program record.