CVE-2022-50903: Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path
Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path by placing malicious executables in specific filesystem locations that will be executed with LocalSystem permissions during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50903?
CVE-2022-50903 has been classified as a medium severity vulnerability due to its potential to allow local users to execute code with elevated privileges.
How do I fix CVE-2022-50903?
To fix CVE-2022-50903, ensure that the service path for ElevationService in Wondershare MobileTrans is properly quoted.
Who is affected by CVE-2022-50903?
CVE-2022-50903 affects all users running Wondershare MobileTrans version 3.5.9.
What type of vulnerability is CVE-2022-50903?
CVE-2022-50903 is an unquoted service path vulnerability allowing potential elevation of privileges.
Can CVE-2022-50903 be exploited remotely?
CVE-2022-50903 cannot be exploited remotely, as it requires local access to the system.