---
id: CVE-2021-44596
title: Wondershare LTD Dr
summary: >-
  Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code
  execution. Due to software design flaws an unauthenticated user can
  communicate over UDP with the "InstallAssistService.exe" service(the service
  is running unde…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: wondershare
product: dr.fone
affected:
  - dr.fone = 2021-12-06
published: '2022-04-29'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-44596'
references:
  - url: >-
      http://packetstormsecurity.com/files/167035/Wondershare-Dr.Fone-12.0.7-Privilege-Escalation.html
    label: cve@mitre.org
  - url: 'https://medium.com/@tomerp_77017/wondershell-a82372914f26'
    label: cve@mitre.org
  - url: 'http://dr.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/167035/Wondershare-Dr.Fone-12.0.7-Privilege-Escalation.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://wondershare.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://medium.com/%40tomerp_77017/wondershell-a82372914f26'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.22929
epssPercentile: 0.97647
exploitAvailable: true
ingestedAt: '2026-07-06T02:09:23.479Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-24T07:52:48.904Z'
---

## Overview

Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to execute malicious executable without any validation from a remote location and gain SYSTEM privileges

## Affected

- `dr.fone = 2021-12-06`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
