Record summary

CVE-2021-44595 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)ExploitDB exploitby Netanel CohenNot analyzed1 file
ExploitDB

PoC details

References

6