LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50690: Wondershare MirrorGo 2.0.11.346 Local Privilege Escalation via Insecure File Permissions

Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to incorrect file permissions on executable files. Unprivileged local users can replace the ElevationService.exe with a malicious file to execute arbitrary code with LocalSystem privileges.

HighCVSS 8.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This vulnerability lets a low-privileged Windows user on a machine running Wondershare MirrorGo 2.0.11.346 potentially become LocalSystem. That is the highest local privilege level. It matters most on shared workstations, kiosks, lab systems, or environments where users can log in locally or attackers already have a foothold.

Executive priority

Prioritize remediation where MirrorGo is installed on shared or high-value endpoints. This is not documented as remotely exploitable, but it can turn a limited local compromise into full system control. If MirrorGo is uncommon or nonessential, removal may be the fastest risk reduction path.

Technical view

Wondershare MirrorGo 2.0.11.346 has incorrect permissions on executable files, mapped to CWE-732. Sources state an unprivileged local user can replace ElevationService.exe and execute arbitrary code as LocalSystem. The CVSS 4.0 score is 8.5, with local attack vector, low complexity, low privileges required, and no user interaction.

Likely exposure

Exposure appears limited to Windows systems with Wondershare MirrorGo version 2.0.11.346 installed. Risk requires local authenticated access, so internet-facing exposure is not the main concern. Organizations should prioritize systems where many users have local access or where endpoint compromise is plausible.

Exploitation context

The source bundle includes an Exploit-DB reference, indicating public exploit information exists. The CVE is not marked as CISA KEV in the provided data, and no cited source confirms active exploitation. Treat it as a post-compromise privilege escalation risk rather than an initial access vulnerability.

Researcher notes

The record names only Wondershare MirrorGo 2.0.11.346 as affected. Evidence in the bundle supports insecure executable permissions and LocalSystem code execution through ElevationService.exe replacement. Patch status is not provided in the sources; avoid assuming fixed versions without vendor confirmation.

Mitigation direction

  • Inventory endpoints for Wondershare MirrorGo 2.0.11.346.
  • Check Wondershare guidance for fixed versions or vendor-recommended remediation.
  • Remove MirrorGo where it is not business-required.
  • Upgrade if a vendor-supported fixed version is available.
  • Limit local interactive access on affected systems.
  • Monitor for unexpected changes to MirrorGo service executables.

Validation and detection

  • Confirm installed MirrorGo version on Windows endpoints.
  • Check whether ElevationService.exe is present in the MirrorGo installation path.
  • Review file permissions on MirrorGo executable directories.
  • Identify non-administrator users with write access to service executables.
  • Verify endpoint controls alert on service binary replacement.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-732: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

Privilege behavior lookup

The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-50690 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.5 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.5CVSS 4.0HighCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NPrimary CVE score

Vulnerability scoring details

Base CVSS 4.0 score

8.5High
CVSS 4.0 vector shape for CVE-2022-50690Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
WondershareWondershare MirrorGo2.0.11.346Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-732 · source CWE mapping

Incorrect Permission Assignment for Critical Resource

Incorrect Permission Assignment for Critical Resource represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.