CVE-2020-27992
HIGHWondershare Dr.fone - Incorrect Permission Assignment
Title source: ruleDescription
Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\DriverInstaller has Full Control for BUILTIN\Users.
References (2)
Core 2
Core References
Product x_refsource_misc
https://drfone.wondershare.com
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/159775/Wondershare-Dr.Fone-3.0.0-Unquoted-Service-Path.html
Scores
CVSS v3
7.8
EPSS
0.0004
EPSS Percentile
11.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-732
Status
published
Products (1)
wondershare/dr.fone
3.0.0
Published
Nov 02, 2020
Tracked Since
Feb 18, 2026