PT-2026-50913 · Matrix42 · Remote Control Host

CVE-2016-20095

·

Published

2026-06-19

·

Updated

2026-06-23

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Matrix42 Remote Control Host version 3.20.0031
Description An unquoted service path issue exists in the FastViewerRemoteService and FastViewerRemoteProxy services. This allows local users to execute arbitrary code with SYSTEM privileges by placing a malicious executable with a crafted name in the Program Files directory, which the service then executes during startup. An unquoted service path occurs when a service path contains spaces and is not enclosed in quotation marks, allowing the operating system to potentially execute a different file with a shorter name from the path.
Recommendations Update Matrix42 Remote Control Host version 3.20.0031 to a version that fixes the unquoted service path in the FastViewerRemoteService and FastViewerRemoteProxy services.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-20095

Affected Products

Remote Control Host