Description
Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.
Problem types
Unquoted Search Path or Element
Product status
Credits
Uriel Yochpaz & Jonatan Schor
References
www.exploit-db.com/exploits/48378 (ExploitDB-48378)
getpopcorntime.is (Popcorn Time Official Homepage)
www.vulncheck.com/...me-update-service-unquoted-service-path (VulnCheck Advisory: Popcorn Time 6.2 - 'Update service' Unquoted Service Path)