CVE-2025-45095: High severity Lavasoft Web Companion vulnerability
Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with write access to the file system could potentially execute arbitrary code with elevated privileges by placing a malicious executable in the unquoted path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-45095?
CVE-2025-45095 is rated as a high severity vulnerability due to the potential for arbitrary code execution with elevated privileges.
How do I fix CVE-2025-45095?
To fix CVE-2025-45095, update to the latest version of Lavasoft Web Companion that resolves the unquoted service path issue.
Who is affected by CVE-2025-45095?
CVE-2025-45095 affects all versions of Lavasoft Web Companion from 8.9.0.1091 to 12.1.3.1037.
What kind of attack can exploit CVE-2025-45095?
CVE-2025-45095 can be exploited by an attacker with write access to the filesystem to execute arbitrary code.
Is there any temporary mitigation for CVE-2025-45095?
As a temporary mitigation for CVE-2025-45095, users should restrict write access to the service path of DCIService.exe.