Unrated severityNVD Advisory· Published Jan 13, 2026· Updated Mar 5, 2026
Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path
CVE-2022-50901
Description
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\ to inject malicious executables that would run with LocalSystem privileges.
Affected products
2= 11.4.9+ 1 more
- (no CPE)range: = 11.4.9
- (no CPE)range: 11.4.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/50755mitreexploit
- www.vulncheck.com/advisories/wondershare-drfone-dfwsidservice-unquoted-service-pathmitrethird-party-advisory
- www.wondershare.commitreproduct
News mentions
0No linked articles in our index yet.