GHSA-h9xj-4798-57hxHighCVSS 8.8
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A...
🔗 CVE IDs covered (1)
📋 Description
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2021-44595
- https://medium.com/@tomerp_77017/wondershell-a82372914f26
- http://dr.com
- http://wondershare.com
- http://packetstormsecurity.com/files/167036/Wondershare-Dr.Fone-12.0.7-Privilege-Escalation.html
- https://medium.com/%40tomerp_77017/wondershell-a82372914f26
- https://github.com/advisories/GHSA-h9xj-4798-57hx