PT-2026-50913 · Matrix42 · Remote Control Host
CVE-2016-20095
·
Published
2026-06-19
·
Updated
2026-06-23
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Matrix42 Remote Control Host version 3.20.0031
Description
An unquoted service path issue exists in the FastViewerRemoteService and FastViewerRemoteProxy services. This allows local users to execute arbitrary code with SYSTEM privileges by placing a malicious executable with a crafted name in the Program Files directory, which the service then executes during startup. An unquoted service path occurs when a service path contains spaces and is not enclosed in quotation marks, allowing the operating system to potentially execute a different file with a shorter name from the path.
Recommendations
Update Matrix42 Remote Control Host version 3.20.0031 to a version that fixes the unquoted service path in the FastViewerRemoteService and FastViewerRemoteProxy services.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Control Host