vendor:
Atheros Coex Service Application
by:
Isabel Lopez
6.5
CVSS
MEDIUM
Unquoted Service Path
427
CWE
Product Name: Atheros Coex Service Application
Affected Version From: 8.0.0.255
Affected Version To: 8.0.0.255
Patch Exists: YES
Related CWE: N/A
CPE: a:atheros:atheros_coex_service_application
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 8.1 (64bits)
2020
Atheros Coex Service Application 8.0.0.255 -‘ZAtheros Bt&Wlan Coex Agent’ Unquoted Service Path
Atheros Coex Service Application 8.0.0.255 has an unquoted service path. The PoC shows that the service 'ZAtheros Bt&Wlan Coex Agent' is running with an unquoted service path. The service is set to auto start.
Mitigation:
The vendor has released a patch to address this vulnerability.