CVE-2021-44596
Wondershare Dr.Fone 12.0.7 - Remote Code Execution (RCE)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges
Wondershare LTD Dr. Fone a partir de la versión 06-12-2021, está afectado por ejecución de código remota. Debido a los defectos de diseño del software, un usuario no autenticado puede comunicarse a través de UDP con el servicio "InstallAssistService.exe" (el servicio es ejecutado bajo privilegios SYSTEM) y manipularlo para ejecutar un ejecutable malicioso sin ninguna comprobación desde una ubicación remota y alcanzar privilegios SYSTEM
Wondershare Dr.Fone version 12.0.7 suffers from a remote privilege escalation vulnerability related to InstallAssistService.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-06 CVE Reserved
- 2022-04-29 CVE Published
- 2022-05-11 First Exploit
- 2024-08-04 CVE Updated
- 2024-10-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://dr.com | Not Applicable | |
https://medium.com/%40tomerp_77017/wondershell-a82372914f26 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50913 | 2022-05-11 | |
http://packetstormsecurity.com/files/167035/Wondershare-Dr.Fone-12.0.7-Privilege-Escalation.html | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://wondershare.com | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wondershare Search vendor "Wondershare" | Dr.fone Search vendor "Wondershare" for product "Dr.fone" | 2021-12-06 Search vendor "Wondershare" for product "Dr.fone" and version "2021-12-06" | - |
Affected
|