Newly published CVEs detail unquoted service path vulnerabilities in two IObit products that can let a low-privileged local attacker gain LocalSystem execution. CVE-2016-20055 affects IObit Advanced SystemCare 10.0.2, specifically the AdvancedSystemCareService10 service, while CVE-2016-20059 affects IObit Malware Fighter 4.3.1 through the IMFservice and LiveUpdateSvc services. Both issues are classified as CWE-428 and carry high-severity CVSS v3.1 and v4.0 ratings reflecting potential impact to confidentiality, integrity, and availability.
In both cases, an attacker with local access can place a malicious executable in a vulnerable service path and wait for the affected service to restart or for the system to reboot, at which point the payload may run with elevated privileges. The Malware Fighter entry cites supporting references including IObit product pages, an Exploit-DB listing, and a VulnCheck advisory, while both CVEs were recorded through disclosures submitted to disclosure@vulncheck.com.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
New CVE records were published for CVE-2016-20055 and CVE-2016-20059, documenting CWE-428 unquoted service path vulnerabilities in IObit Advanced SystemCare 10.0.2 and IObit Malware Fighter 4.3.1. The entries describe affected services, note high-severity CVSS v3.1 and v4.0 scores, and reference supporting advisories and exploit material.
On 2026-04-04, disclosure@vulncheck.com received reports for two unquoted service path privilege-escalation vulnerabilities affecting IObit Advanced SystemCare 10.0.2 and IObit Malware Fighter 4.3.1. Both flaws allow a low-privileged local attacker to place a malicious executable in the service path and gain LocalSystem execution when the service restarts or the system reboots.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.