vendor:
Dr Fone
by:
Thurein Soe
7.8
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Dr Fone
Affected Version From: 12.9.2006
Affected Version To: 12.9.2006
Patch Exists: YES
Related CWE: CVE-2023-27010
CPE: a:wondershare:dr_fone
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=27010, https://www.infosecmatter.com/nessus-plugin-library/?id=23409, https://www.infosecmatter.com/nessus-plugin-library/?id=27000, https://www.infosecmatter.com/nessus-plugin-library/?id=37271, https://www.infosecmatter.com/nessus-plugin-library/?id=35415, https://www.infosecmatter.com/nessus-plugin-library/?id=35421, https://www.infosecmatter.com/nessus-plugin-library/?id=42836, https://www.infosecmatter.com/nessus-plugin-library/?id=107968, https://www.infosecmatter.com/nessus-plugin-library/?id=107539, https://www.infosecmatter.com/nessus-plugin-library/?id=42829
Platforms Tested: Windows 10
2023
Wondershare Dr Fone 12.9.6 – Privilege Escalation
Wondershare Dr Fone version 12.9.6 running services named 'WsDrvInst' on Windows have weak service permissions and are susceptible to local privilege escalation vulnerability. Weak service permissions run with system user permission, allowing a standard user/domain user to elevate to administrator privilege upon successfully modifying the service or replacing the affected executable. DriverInstall.exe gave modification permission to any authenticated users in the windows operating system, allowing standard users to modify the service and leading to Privilege Escalation.
Mitigation:
Ensure that service permissions are configured correctly and that only authorized users are allowed to modify services.