vendor:
Dr. Fone
by:
Esant1490
7.2
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: Dr. Fone
Affected Version From: 4.0.8
Affected Version To: 4.0.8
Patch Exists: NO
Related CWE:
CPE: a:wondershare:dr.fone:4.0.8
Platforms Tested: Windows 10 Pro x64 en
2022
Dr. Fone v4.0.8- ‘net_updater32.exe’ Unquoted Service Path
A successful attempt to exploit this vulnerability could allow to execute code during startup or reboot with the elevated privileges.
Mitigation:
Ensure that all services have a fully qualified path to the executable file.