CVE-2022-50900: Wondershare Dr.Fone 12.0.18 - 'Wondershare InstallAssist' Unquoted Service Path
Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path to insert malicious code that will be executed with LocalSystem permissions during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50900?
CVE-2022-50900 is rated as a high-severity vulnerability due to its potential to allow local users to execute arbitrary code with elevated privileges.
How do I fix CVE-2022-50900?
To resolve CVE-2022-50900, ensure that the Wondershare InstallAssist service path is properly quoted to prevent unauthorized code execution.
Who is affected by CVE-2022-50900?
CVE-2022-50900 affects local users of Wondershare Dr.Fone version 12.0.18 and potentially other versions with similar misconfigurations.
What type of vulnerability is CVE-2022-50900?
CVE-2022-50900 is classified as an unquoted service path vulnerability, allowing privilege escalation.
Can CVE-2022-50900 be exploited remotely?
CVE-2022-50900 requires local access to exploit, as it is a vulnerability that affects local users rather than remote attackers.