CVE-2022-50901: Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\ to inject malicious executables that would run with LocalSystem privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50901?
CVE-2022-50901 is considered to have a high severity level due to the potential for arbitrary code execution.
How do I fix CVE-2022-50901?
To fix CVE-2022-50901, you need to update Wondershare Dr.Fone to the latest version that addresses the unquoted service path vulnerability.
Who is affected by CVE-2022-50901?
Users of Wondershare Dr.Fone version 11.4.9 are affected by CVE-2022-50901.
What type of vulnerability is CVE-2022-50901?
CVE-2022-50901 is classified as an unquoted service path vulnerability.
Can CVE-2022-50901 be exploited remotely?
CVE-2022-50901 is not considered a remote vulnerability; it requires local access to exploit.