CVE-2021-44596
CRITICALWondershare Dr.fone - Remote Code Execution
Title source: ruleDescription
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges
Exploits (1)
exploitdb
WORKING POC
by Netanel Cohen · pythonremotewindows
https://www.exploit-db.com/exploits/50913
References (4)
Scores
CVSS v3
9.8
EPSS
0.4278
EPSS Percentile
97.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
wondershare/dr.fone
2021-12-06
Published
Apr 29, 2022
Tracked Since
Feb 18, 2026