CVE-2021-44596
critical · 9.8Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges
9.8
CVSS
22.9%
EPSS (exploit prob.)
98th
EPSS percentile
2022-04-29
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wondershare | dr.fone | 2021-12-06 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/167035/Wondershare-Dr.Fone-12.0.7-Privilege-Escalation.html
- https://medium.com/@tomerp_77017/wondershell-a82372914f26
- http://packetstormsecurity.com/files/167035/Wondershare-Dr.Fone-12.0.7-Privilege-Escalation.html
- https://medium.com/%40tomerp_77017/wondershell-a82372914f26
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-44596