Junglewise Threat Intelligence

CVE-2016-20089: Iperius Remote unquoted service path in IperiusRemotesvc

CVE-2016-20089 · Severity: high · CVSS 7.8 · Published 2026-06-19

Executive brief

Iperius Remote, a software used for remote desktop support and unattended access, contains a security flaw in how its Windows service is registered. If the software is installed in a folder path that contains spaces, a local user with low privileges can trick the system into running a malicious program instead of the legitimate one. This could allow an attacker to gain full administrative control (SYSTEM privileges) over the computer, potentially leading to data theft or complete system compromise.

Technical details

Iperius Remote 1.7.0 contains an unquoted service path vulnerability (CWE-428) within its service installation component. The application registers its Windows service (IperiusRemotesvc) using a binary path that lacks quotation marks. If the service is installed in a directory path containing spaces (e.g., C:\Program Files\...), the Windows Service Control Manager will attempt to locate and execute binaries at each space-delimited intercept point. A local attacker with permission to write to the parent directory can place a malicious executable (e.g., C:\Program.exe) that will be executed with SYSTEM privileges upon service startup or system reboot. While the software is portable, the vulnerability is triggered when a user explicitly chooses to install it as a persistent Windows service.

Affected products

  • Iperiusremote Iperius Remote 1.7.0 and earlier

Timeline

  • 2016-09-26: disclosed: Initial public exploit and advisory published by Tulpa
  • 2026-06-19: advisory: CVE record published/updated in NVD dataset

References