VulnerabilityDeferred
CVE-2020-36979
Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration.
HIGH 8.5EPSS 0.17%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.
- CVSS 4.0
- 8.5 HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Source
- disclosure@vulncheck.com
References
- https://www.boostbyreason.com/resource-file-9102-ath_coexagent-exe.aspx
- https://www.exploit-db.com/exploits/49053
- https://www.file.net/process/ath_coexagent.exe.html
- https://www.vulncheck.com/advisories/atheros-coex-service-application-zatheros-btwlan-coex-agent-unquoted-service-path
- https://www.exploit-db.com/exploits/49053
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.