vendor:
MobileTrans
by:
Thurein Soe
7.8
CVSS
HIGH
Weak Service Privilege Escalation
317
CWE
Product Name: MobileTrans
Affected Version From: MobileTrans version 4.0.11
Affected Version To: MobileTrans version 4.0.11
Patch Exists: NO
Related CWE: CVE-2023-31748
CPE: a:wondershare:mobiletrans:4.0.11
Platforms Tested: Windows 10 (Version 10.0.19045.2965)
2023
MobileTrans 4.0.11 – Weak Service Privilege Escalation
MobileTrans version 4.0.11 was being suffered a weak service permission vulnerability that allows a normal window user to elevate to local admin. The 'ElevationService' service name was installed, while the MobileTrans version 4.0.11 was installed in the window operating system. The service 'ElevationService' allows the local user to elevate to the local admin as The 'ElevationService' run with system privileges. Effectively, the local user is able to elevate to local admin upon successfully modifying the service or replacing the affected executable.
Mitigation:
Unknown