Wondershare Dr.Fone Privilege Scalation Vulnerability
- Dr.Fone, 13.5.21 version.
INCIBE has coordinated the publication of a high severity vulnerability affecting Wondershare's Dr.Fone version 13.5.21, a solution for data transfer and recovery on mobile devices, which has been discovered by Enrique Fernández Lorenzo (bighound).
This vulnerability has been assigned the following code, CVSS v3.1 base score, CVSS vector and vulnerability type CWE:
- CVE-2025-0834 : CVSS v3.1: 7.8 | CVSS AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | CWE-269
There is no reported solution at this time.
CVE-2025-0834: privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Wondershare\wsServices\ElevationService.exe’ with a malicious binary. This binary will be executed by SYSTEM automatically.