vendor:
Web Companion
by:
Debashis Pal
5.5
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: Web Companion
Affected Version From: 5.1.1035.1047
Affected Version To: 5.1.1035.1047
Patch Exists: NO
Related CWE:
CPE: a:web_companion:web_companion:5.1.1035.1047
Platforms Tested: Windows 7 SP1(64bit)
2019
Web Companion versions 5.1.1035.1047 – ‘WCAssistantService’ Unquoted Service Path
Web Companion versions 5.1.1035.1047 service 'WCAssistantService' has an unquoted service path. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.
Mitigation:
To mitigate this vulnerability, the vendor should ensure that the service path is quoted correctly. Users should also update to the latest version of Web Companion.