Vulnerability CVE-2020-27992


Published: 2020-11-02   Modified: 2020-11-03

Description:
Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\DriverInstaller has Full Control for BUILTIN\Users.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Wondershare Dr.Fone 3.0.0 Unquoted Service Path
Andrea Intilange...
31.10.2020

 References:
https://drfone.wondershare.com
https://packetstormsecurity.com/files/159775/Wondershare-Dr.Fone-3.0.0-Unquoted-Service-Path.html

Copyright 2024, cxsecurity.com

 

Back to Top