vendor:
Adaware Web Companion
by:
Mariela L Martínez Hdez
5.5
CVSS
MEDIUM
Unquoted Service Path
428
CWE
Product Name: Adaware Web Companion
Affected Version From: 4.8.2078.3950
Affected Version To: 4.8.2078.3950
Patch Exists: NO
Related CWE:
CPE: a:lavasoft:web_companion:4.8.2078.3950
Platforms Tested: Windows 10 Home (64 bits)
2019
Adaware Web Companion version 4.8.2078.3950 – ‘WCAssistantService’ Unquoted Service Path
Adaware Web Companion version 4.8.2078.3950 service 'WCAssistantService' has an unquoted service path. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user's code would execute with the elevated privileges of the application.
Mitigation:
The vendor should update the service path to include quotes around the executable path. Users should also ensure that they have the latest version of Adaware Web Companion installed.