top of page
perceptive_background_267k.jpg

Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbi…

Published:

2 februari 2026 om 23:00:00

Alert date:

3 februari 2026 om 17:02:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Operating Systems

CVE-2020-37102 affects Adaware Web Companion version 4.9.2159, containing an unquoted service path vulnerability in the WCAssistantService component. This vulnerability allows local attackers to exploit the unquoted binary path by injecting malicious executables. When the service starts up, these malicious executables are executed with LocalSystem privileges, potentially allowing arbitrary code execution. The vulnerability enables privilege escalation attacks through path manipulation during service initialization.

Technical details

Mitigation steps:

Affected products:

Adaware Web Companion

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page