PT-2026-50905 · Unknown · Fortitude Http
CVE-2016-20087
·
Published
2026-06-19
·
Updated
2026-06-22
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortitude HTTP version 1.0.4.0
Description
An unquoted service path issue exists, allowing local users to execute arbitrary code with elevated privileges. This occurs because the service binary path is not enclosed in quotes, enabling attackers to place malicious executables in the system root path. These files can then be executed with SYSTEM privileges during service startup or a system reboot.
Recommendations
Update Fortitude HTTP version 1.0.4.0 to a version where the service path is properly quoted.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortitude Http