Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain administrative access.
History

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Py Software
Py Software active Webcam
Vendors & Products Py Software
Py Software active Webcam

Thu, 15 Jan 2026 23:45:00 +0000

Type Values Removed Values Added
Description Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path by placing malicious executables in specific directory locations to gain administrative access.
Title Active WebCam 11.5 - Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-15T23:25:41.368Z

Updated: 2026-01-16T21:12:13.928Z

Reserved: 2026-01-14T14:39:44.738Z

Link: CVE-2021-47790

cve-icon Vulnrichment

Updated: 2026-01-16T15:53:11.723Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T00:16:22.640

Modified: 2026-01-16T22:16:14.663

Link: CVE-2021-47790

cve-icon Redhat

No data.