Vulnerability Description
Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain administrative access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pysoft | Active Webcam | 11.5 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/50273Exploit
- https://www.pysoft.com/Product
- https://www.techspot.com/downloads/175-active-webcam.htmlProduct
- https://www.vulncheck.com/advisories/active-webcam-unquoted-service-pathThird Party Advisory
- https://www.exploit-db.com/exploits/50273Exploit
FAQ
What is CVE-2021-47790?
CVE-2021-47790 is a vulnerability with a CVSS score of 7.8 (HIGH). Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured servic...
How severe is CVE-2021-47790?
CVE-2021-47790 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47790?
Check the references section above for vendor advisories and patch information. Affected products include: Pysoft Active Webcam.