CVE-2020-27992: High severity wondershare dr.fone vulnerability
Published Oct 31, 2020
·Updated
Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\DriverInstaller has Full Control for BUILTIN\Users.
Affected Software
1 affected component
Wondershare Dr.Fone=3.0.0
Event History
Oct 31, 2020
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-27992?
CVE-2020-27992 is classified as a medium severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2020-27992?
To fix CVE-2020-27992, ensure that the permissions for the DriverInstaller directory are restricted to prevent unauthorized access and modification.
3
Who is affected by CVE-2020-27992?
CVE-2020-27992 affects local users who have access to the Wondershare Dr.Fone application version 3.0.0.
4
What type of vulnerability is CVE-2020-27992?
CVE-2020-27992 is a local privilege escalation vulnerability.
5
What can attackers achieve with CVE-2020-27992?
Attackers exploiting CVE-2020-27992 can gain elevated privileges on the affected system.