CVE-2022-50904
8.4Wondershare · UBackit
Wondershare UBackit 2.0.5 is vulnerable to an unquoted service path flaw in the wsbackup service, allowing local attackers to execute arbitrary code with LocalSystem privileges.
Executive summary
A local privilege escalation vulnerability in Wondershare UBackit 2.0.5 allows unauthorized users to gain elevated system permissions by exploiting an unquoted service path.
Vulnerability
The software contains an unquoted service path vulnerability (CWE-428) within the wsbackup service. A local attacker with low privileges can place a malicious executable in the service path, which the system will execute with LocalSystem privileges during the service startup process.
Business impact
Successful exploitation of this vulnerability allows a local user to escalate their privileges to LocalSystem, effectively granting them full control over the compromised machine. Given the CVSS score of 8.4, this poses a severe risk, as it enables attackers to bypass security controls, install persistent backdoors, and exfiltrate sensitive data. This vulnerability could lead to total system compromise and significant reputational damage if exploited within an enterprise environment.
Remediation
Immediate Action: Since no official patch is currently identified, users should disable the affected wsbackup service or uninstall Wondershare UBackit 2.0.5 until a secure version is released.
Proactive Monitoring: Monitor system logs for the execution of unauthorized binaries from the installation directory of Wondershare UBackit and review service configuration changes.
Compensating Controls: Implement strict file system permissions on the installation directory to prevent non-privileged users from writing or modifying files within the path of the affected service.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the Exploit-DB entry 50758.
Analyst recommendation
The severity of this vulnerability, combined with the availability of a functional proof-of-concept, necessitates immediate action. Organizations should audit their environments for the presence of Wondershare UBackit 2.0.5 and prioritize the removal or containment of the affected service to prevent unauthorized privilege escalation.
More Wondershare CVEs
Sources
Originally found and disclosed by Luis Martinez, per the CVE Program record.
- ExploitDB-50758 Exploit / PoC
- Vendor Homepage
- VulnCheck Advisory: Wondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service Path Third-party advisory