CVE-2020-27992: Wondershare Dr.fone

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\DriverInstaller has Full Control for BUILTIN\Users.

Affected products

Published 2020-11-02. Last modified 2026-06-17.