Description
Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.
Problem types
Unquoted Search Path or Element
Product status
Credits
Isabel Lopez
References
www.exploit-db.com/exploits/49053
www.exploit-db.com/exploits/49053 (ExploitDB-49053)
www.file.net/process/ath_coexagent.exe.html (Vendor Homepage)
www.boostbyreason.com/...ce-file-9102-ath_coexagent-exe.aspx (Software Download Link)
www.vulncheck.com/...btwlan-coex-agent-unquoted-service-path (VulnCheck Advisory: Atheros Coex Service Application 8.0.0.255 -'ZAtheros Bt&Wlan Coex Agent' Unquoted Service Path)