Security readout for executives and security teams
Plain-English summary
This vulnerability lets a low-privileged Windows user on a machine running Wondershare MirrorGo 2.0.11.346 potentially become LocalSystem. That is the highest local privilege level. It matters most on shared workstations, kiosks, lab systems, or environments where users can log in locally or attackers already have a foothold.
Executive priority
Prioritize remediation where MirrorGo is installed on shared or high-value endpoints. This is not documented as remotely exploitable, but it can turn a limited local compromise into full system control. If MirrorGo is uncommon or nonessential, removal may be the fastest risk reduction path.
Technical view
Wondershare MirrorGo 2.0.11.346 has incorrect permissions on executable files, mapped to CWE-732. Sources state an unprivileged local user can replace ElevationService.exe and execute arbitrary code as LocalSystem. The CVSS 4.0 score is 8.5, with local attack vector, low complexity, low privileges required, and no user interaction.
Likely exposure
Exposure appears limited to Windows systems with Wondershare MirrorGo version 2.0.11.346 installed. Risk requires local authenticated access, so internet-facing exposure is not the main concern. Organizations should prioritize systems where many users have local access or where endpoint compromise is plausible.
Exploitation context
The source bundle includes an Exploit-DB reference, indicating public exploit information exists. The CVE is not marked as CISA KEV in the provided data, and no cited source confirms active exploitation. Treat it as a post-compromise privilege escalation risk rather than an initial access vulnerability.
Researcher notes
The record names only Wondershare MirrorGo 2.0.11.346 as affected. Evidence in the bundle supports insecure executable permissions and LocalSystem code execution through ElevationService.exe replacement. Patch status is not provided in the sources; avoid assuming fixed versions without vendor confirmation.
Mitigation direction
- Inventory endpoints for Wondershare MirrorGo 2.0.11.346.
- Check Wondershare guidance for fixed versions or vendor-recommended remediation.
- Remove MirrorGo where it is not business-required.
- Upgrade if a vendor-supported fixed version is available.
- Limit local interactive access on affected systems.
- Monitor for unexpected changes to MirrorGo service executables.
Validation and detection
- Confirm installed MirrorGo version on Windows endpoints.
- Check whether ElevationService.exe is present in the MirrorGo installation path.
- Review file permissions on MirrorGo executable directories.
- Identify non-administrator users with write access to service executables.
- Verify endpoint controls alert on service binary replacement.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-732: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupExecution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupPrivilege behavior lookup
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2022-50690 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 8.5 (4.0)
- Known Exploited
- No
- Published
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N——Primary CVE scoreVulnerability scoring details
Base CVSS 4.0 score
8.5HighVector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source materials
- CVE List V5 sourceCVE List V5
- ExploitDB-50787CVE reference · exploit
- Wondershare Official HomepageCVE reference · product
- VulnCheck Advisory: Wondershare MirrorGo 2.0.11.346 Local Privilege Escalation via Insecure File PermissionsCVE reference · third-party-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Incorrect Permission Assignment for Critical Resource
Incorrect Permission Assignment for Critical Resource represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
