Security
Headlines
HeadlinesLatestCVEs

Headline

Wondershare Dr Fone 12.9.6 Weak Permissions / Privilege Escalation

Wondershare Dr Fone version 12.9.6 suffers from a weak service permission vulnerability that can allow for privilege escalation.

Packet Storm
#vulnerability#ios#android#windows#auth

Executive Summary:

Product Name: Wondershare Dr. Fone
Vendor Home Page: https://drfone.wondershare.com
Affected Version(s): Dr Fone version 12.9.6
Vulnerability Type: Execution with Unnecessary Privileges (CWE-250)
CVE Reference: CVE-2023-27010.
Credit: Thurein Soe

Vendor Description:

Wondershare Dr. Fone is an app designed to help with data recovery and
management for all Android and iOS devices.

Vulnerability description:

Wondershare Dr Fone version 12.9.6 running services named “WsDrvInst” on
Windows have weak service permissions and are susceptible to local
privilege escalation vulnerability. Weak service permissions run with
system user permission, allowing a standard user/domain user to elevate to
administrator privilege upon successfully modifying the service or
replacing the affected executable. DriverInstall.exe gave modification
permission to any authenticated users in the windows operating system,
allowing standard users to modify the service and leading to Privilege
Escalation.

C:\Users\NyaMeeEain\Desktop>cacls “C:\Program Files
(x86)\Wondershare\drfone\Addins\Repair\DriverInstall.exe”
C:\Program Files (x86)\Wondershare\drfone\Addins\Repair\DriverInstall.exe
Everyone:(ID)F

NT AUTHORITY\SYSTEM:(ID)F

BUILTIN\Administrators:(ID)F

BUILTIN\Users:(ID)R

APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES:(ID)R

APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES:(ID)R
C:\Users\NyaMeeEain\Desktop>sc qc WsDrvInst
SERVICE_NAME: WsDrvInst
TYPE : 10 WIN32_OWN_PROCESS
START_TYPE : 3 DEMAND_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : “C:\Program Files
(x86)\Wondershare\drfone\Addins\Repair\DriverInstall.exe”
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Wondershare Driver Install Service
DEPENDENCIES : RPCSS
SERVICE_START_NAME : LocalSystem

References:
https://cwe.mitre.org/data/definitions/250.html

Related news

CVE-2023-27010: CWE-250: Execution with Unnecessary Privileges (4.10)

Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to escalate privileges via modifying or overwriting the executable.

Packet Storm: Latest News

Scapy Packet Manipulation Tool 2.6.1