PoC Index

CVE-2021-44596

HIGH 10.0EPSS 22.9%

Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
22.93% chance of exploitation in the next 30 days, 98th percentile
Published
2022-04-29
Updated
2026-07-09

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related