PT-2025-4065 · Wondershare · Wondershare Dr.Fone
Bighound
+1
·
Published
2025-01-30
·
Updated
2025-01-30
·
CVE-2025-0834
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wondershare Dr.Fone version 13.5.21
Description
A privilege escalation vulnerability has been found in Wondershare Dr.Fone. This issue could allow an attacker to escalate privileges by replacing the binary
C:ProgramDataWondersharewsServicesElevationService.exe with a malicious binary. The malicious binary will be executed by SYSTEM automatically.Recommendations
For Wondershare Dr.Fone version 13.5.21, consider replacing the vulnerable binary
ElevationService.exe with a secure version or restricting access to the C:ProgramDataWondersharewsServices directory to prevent exploitation. As a temporary workaround, consider disabling the ElevationService.exe binary until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wondershare Dr.Fone