CVE-2016-20058: Netgate Amiti Antivirus

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.

Affected products

  • Netgate Amiti Antivirus: up to and including 23.0.305

Published 2026-04-04. Last modified 2026-07-21.