Description
Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to the Administrators group with full system access.
Problem types
Incorrect Permission Assignment for Critical Resource
Product status
Credits
ZwX
References
www.exploit-db.com/exploits/47667 (ExploitDB-47667)
www.wondershare.net/ (Wondershare Official Homepage)
www.wondershare.net/mobilego/ (MobileGo Product Page)
www.vulncheck.com/...ries/mobilego-insecure-file-permissions (VulnCheck Advisory: MobileGo 8.5.0 - Insecure File Permissions)