Newly documented vulnerabilities in Spy Emergency build 23.0.205 and sheed AntiVirus 2.3 allow local attackers to escalate privileges to LocalSystem through unquoted service path flaws classified as CWE-428. The affected services are SpyEmrgHealth and SpyEmrgSrv in Spy Emergency, and ShavProt in sheed AntiVirus. In each case, a low-privileged user can place a malicious executable in a path segment that Windows may incorrectly parse because the service executable path is not enclosed in quotes.
If the vulnerable service is restarted or the host is rebooted, Windows can execute the attacker-controlled binary with SYSTEM-level privileges, creating a high-impact local privilege escalation path affecting confidentiality, integrity, and availability. The issues are tracked as CVE-2016-20056 for Spy Emergency and CVE-2016-20061 for sheed AntiVirus, with both records referencing vendor resources, Exploit-DB, and VulnCheck advisories.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry documented a local privilege escalation vulnerability in sheed AntiVirus 2.3 involving an unquoted service path in the ShavProt service. A local attacker can exploit the issue by placing a malicious binary in the unquoted path and triggering a service restart or reboot to execute code as LocalSystem.
A CVE entry documented an unquoted service path privilege escalation vulnerability in Spy Emergency build 23.0.205 affecting the SpyEmrgHealth and SpyEmrgSrv services. The flaw allows a low-privileged local attacker to place a malicious executable in the service path and gain LocalSystem privileges when the service restarts or the system reboots.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.