VYPR
Vendor

Iobit

Products
19
CVEs
84
Across products
117
Status
Private

Products

19

Recent CVEs

84
View all 84 CVEs →
  • CVE-2022-24562CriJun 16, 2022
    risk 0.71cvss 9.8epss 0.53

    In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

  • CVE-2021-21789HigJul 7, 2021
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0e0, the first dword passed in the input buffer is the device port to write to and the dword at offset 4 is the…

  • CVE-2021-21788HigJul 7, 2021
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0dc, the first dword passed in the input buffer is the device port to write to and the word at offset 4 is the…

  • CVE-2021-21787HigJul 7, 2021
    risk 0.57cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0d8, the first dword passed in the input buffer is the device port to write to and the byte at offset 4 is the…

  • CVE-2018-16711HigSep 26, 2018
    risk 0.57cvss 8.8epss 0.02

    IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction…

  • CVE-2022-37197HigNov 18, 2022
    risk 0.54cvss 7.8epss 0.01

    IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.

  • CVE-2020-37232HigMay 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Attackers can place malicious executables in the system root path that will be…

  • CVE-2020-37223HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and…

  • CVE-2016-20059HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.00

    IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege…

  • CVE-2016-20055HigApr 4, 2026
    risk 0.51cvss 7.8epss 0.00

    IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when…

  • CVE-2020-36952HigJan 26, 2026
    risk 0.51cvss 7.8epss 0.00

    IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would…

  • CVE-2024-7326HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the…

  • CVE-2024-7325HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is some unknown functionality in the library VCL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a…

  • CVE-2024-7324HigJul 31, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality in the library madbasic_.bpl of the component BPL Handler. The manipulation leads to uncontrolled search path. Local…

  • CVE-2022-24139HigJul 6, 2022
    risk 0.51cvss 7.8epss 0.00

    In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named pipes, because of that during login the…

  • CVE-2022-24138HigJul 6, 2022
    risk 0.51cvss 7.8epss 0.01

    IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the…

  • CVE-2021-44968HigFeb 18, 2022
    risk 0.51cvss 7.8epss 0.00

    A Use after Free vulnerability exists in IOBit Advanced SystemCare 15 pro via requests sent in sequential order using the IOCTL driver codes, which could let a malicious user execute arbitrary code or a Denial of Service (system crash). IOCTL list: iobit_ioctl = [0x8001e01c,…

  • CVE-2021-21786HigJul 7, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to increased privileges. An attacker can send a malicious IRP to trigger this vulnerability.

  • CVE-2020-23864HigOct 27, 2020
    risk 0.51cvss 7.8epss 0.01

    An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the WindowsApps folder.

  • CVE-2020-14975HigJun 23, 2020
    risk 0.51cvss 7.8epss 0.01

    The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code 0x222124.