CVE-2019-25287: Adaware Web Companion version 4.8.2078.3950 - 'WCAssistantService' Unquoted Service Path
Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious code that would execute with LocalSystem privileges during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25287?
CVE-2019-25287 is considered a high severity vulnerability due to the potential for local users to execute code with elevated privileges.
How do I fix CVE-2019-25287?
To fix CVE-2019-25287, ensure that the service path for WCAssistantService is correctly quoted in the installation directory.
Which version of Adaware Web Companion is affected by CVE-2019-25287?
CVE-2019-25287 affects Adaware Web Companion version 4.8.2078.3950.
What type of vulnerability is CVE-2019-25287?
CVE-2019-25287 is classified as an unquoted service path vulnerability.
Can CVE-2019-25287 be exploited remotely?
CVE-2019-25287 cannot be exploited remotely; it requires local access to the affected machine.