CVE-2022-50903

Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path by placing malicious executables in specific filesystem locations that will be executed with LocalSystem permissions during service startup.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wondershare:mobiletrans:3.5.9:*:*:*:*:*:*:*

History

28 Jan 2026, 19:53

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50756 - () https://www.exploit-db.com/exploits/50756 - Exploit
References () https://www.vulncheck.com/advisories/wondershare-mobiletrans-elevationservice-unquoted-service-path - () https://www.vulncheck.com/advisories/wondershare-mobiletrans-elevationservice-unquoted-service-path - Third Party Advisory
References () https://www.wondershare.com/ - () https://www.wondershare.com/ - Product
First Time Wondershare mobiletrans
Wondershare
CPE cpe:2.3:a:wondershare:mobiletrans:3.5.9:*:*:*:*:*:*:*

13 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:15

Updated : 2026-01-28 19:53


NVD link : CVE-2022-50903

Mitre link : CVE-2022-50903

CVE.ORG link : CVE-2022-50903


JSON object : View

Products Affected

wondershare

  • mobiletrans
CWE
CWE-428

Unquoted Search Path or Element