vendor:
Popcorn Time
by:
Uriel Yochpaz & Jonatan Schor
7.5
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: Popcorn Time
Affected Version From: 6.2.1.14
Affected Version To: 6.2.1.14
Patch Exists: NO
Related CWE:
CPE: a:popcorn_time:popcorn_time:6.2.1.14
Platforms Tested: Windows 10, 7
2020
Popcorn Time 6.2 – ‘Update service’ Unquoted Service Path
Popcorn Time For Windows installs as a service with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
The vendor should fix the unquoted service path vulnerability by properly quoting the service path.