Active Webcam 115 Unquoted Service Path Patched [new] 〈Simple — Hacks〉

Active WebCam version 11.5 was found to have a critical security flaw known as an unquoted service path vulnerability (tracked as CVE-2021-47790). This allows a local attacker to gain administrative control over your computer. What is the Vulnerability?

C:\Program Files\Active WebCam\webcam.exe

C:\Program Files\Active Webcam\webcam115.exe active webcam 115 unquoted service path patched

# Query the ImagePath value path_val, _ = winreg.QueryValueEx(key, "ImagePath") winreg.CloseKey(key)

Alternatively, the attacker could use C:\Program Files\Active.exe as the hijack target. Active WebCam version 11

This article explores what the Active Webcam 115 unquoted service path vulnerability was, how it allowed for system-level exploitation, and how the issue is effectively patched. What is an Unquoted Service Path? C:\Program Files\Active Webcam\webcam115

4.3 Affected Systems