dr.com
http://dr.com/ CVE-2021-44596
CRITICAL
Wondershare Dr.Fone 12.0.7 - Remote Code Execution (RCE)
Record summary
CVE-2021-44596 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWondershare Dr.Fone 12.0.7 - Remote Code Execution (RCE)ExploitDB exploitby Netanel CohenNot analyzed1 file
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/167035/Wondershare-Dr.Fone-12.0.7-Privilege-Escalation.html wondershare.com
http://wondershare.com/ medium.com
https://medium.com/%40tomerp_77017/wondershell-a82372914f26 medium.com
https://medium.com/@tomerp_77017/wondershell-a82372914f26 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-44596