CVE-2021-44595
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the...
- Published
- Apr 29, 2022
- Updated
- Jul 9, 2026
- Assigning CNA
- mitre
- Evidence observed
- May 11, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 97.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.
Sources
2- WonderShellExploit
Proof-of-concept exploit for CVE-2021-44595 and CVE-2021-44596 in Wondershare Dr.Fone, enabling remote code execution as SYSTEM via vulnerable services.
Netanel Cohen · windows · May 11, 2022
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.