


Perceptive Security
SOC/SIEM Consultancy

Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbiā¦
Published:
2 February 2026 at 23:00:00
Alert date:
3 February 2026 at 17:02:27
Source:
nvd.nist.gov
Security Tools, Operating Systems
CVE-2020-37102 affects Adaware Web Companion version 4.9.2159, containing an unquoted service path vulnerability in the WCAssistantService component. This vulnerability allows local attackers to exploit the unquoted binary path by injecting malicious executables. When the service starts up, these malicious executables are executed with LocalSystem privileges, potentially allowing arbitrary code execution. The vulnerability enables privilege escalation attacks through path manipulation during service initialization.
Technical details
Mitigation steps:
Affected products:
Adaware Web Companion
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2020-37102
http://webcompanion.com/
http://webcompanion.com/LP-WC002/index.php?partner=LU150701WEBDIRECT&campaign=www.doc2pdf.com&search=2&homepage=2&bd=2
https://www.exploit-db.com/exploits/47852
https://www.vulncheck.com/advisories/adaware-web-companion-wcassistantservice-unquoted-service-path
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
