Описание
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\ to inject malicious executables that would run with LocalSystem privileges.
Ссылки
- Exploit
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:wondershare:dr.fone:11.4.9:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00012
Низкий
8.4 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-428
Связанные уязвимости
CVSS3: 8.4
github
25 дней назад
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\ to inject malicious executables that would run with LocalSystem privileges.
EPSS
Процентиль: 1%
0.00012
Низкий
8.4 High
CVSS3
7.8 High
CVSS3
Дефекты
CWE-428