VYPR

Vendor CVEs

Iobit

All CVEs

68 total · sorted by risk
  • CVE-2021-21788Jul 7, 2021
    risk 0.00cvss epss 0.00

    A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0dc, the first dword passed in the input buffer is the device port to write to and the word at offset 4 is the…

  • CVE-2021-21787Jul 7, 2021
    risk 0.00cvss epss 0.00

    A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0d8, the first dword passed in the input buffer is the device port to write to and the byte at offset 4 is the…

  • CVE-2020-10234Feb 5, 2021
    risk 0.00cvss epss 0.04

    The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device driver. If the user provides a NULL entry for the dwIoControlCode parameter, a kernel panic (aka BSOD) follows. The IOCTL codes can be found in…

  • CVE-2020-23864Oct 27, 2020
    risk 0.00cvss epss 0.01

    An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the WindowsApps folder.

  • CVE-2020-15401Jun 30, 2020
    risk 0.00cvss epss 0.00

    IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link.

  • CVE-2020-14974Jun 23, 2020
    risk 0.00cvss epss 0.01

    The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124.

  • CVE-2020-14975Jun 23, 2020
    risk 0.00cvss epss 0.01

    The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code 0x222124.

  • CVE-2020-14990Jun 22, 2020
    risk 0.00cvss epss 0.01

    IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.

  • CVE-2019-6494Apr 30, 2019
    risk 0.00cvss epss 0.01

    IMFForceDelete.sys in IObit Malware Fighter 6.2 allows a low privileged user to send IOCTL 0x8016E000 along with a user defined string to a file; that file will be promptly deleted regardless of access controls.

  • CVE-2019-6493Apr 11, 2019
    risk 0.00cvss epss 0.00

    SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user defined bytes and size when IOCTL 0x9C401CC0 is called. This kernel pointer can be leaked if the kernel pool becomes a "big" pool.

  • CVE-2019-6492Mar 18, 2019
    risk 0.00cvss epss 0.00

    SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user defined bytes and size when IOCTL 0x9C401CC4 is called. This kernel pointer can be leaked if the kernel pool becomes a "big" pool.

  • CVE-2018-19086Nov 10, 2018
    risk 0.00cvss epss 0.01

    RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E040 with a size larger than 8 bytes. This can lead to denial of service or code execution with root privileges.

  • CVE-2018-19085Nov 10, 2018
    risk 0.00cvss epss 0.01

    RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E048 with a size larger than 8 bytes. This can lead to denial of service or code execution with root privileges.

  • CVE-2018-19087Nov 10, 2018
    risk 0.00cvss epss 0.01

    RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E044 with a size larger than 8 bytes. This can lead to denial of service or code execution with root privileges.

  • CVE-2018-19084Nov 10, 2018
    risk 0.00cvss epss 0.01

    RegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E05C with a size larger than 8 bytes. This can lead to denial of service or code execution with root privileges.

  • CVE-2018-18714Nov 1, 2018
    risk 0.00cvss epss 0.01

    RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This can lead to denial of service (DoS) or code execution with root privileges.

  • CVE-2018-18026Oct 19, 2018
    risk 0.00cvss epss 0.01

    IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of…

  • CVE-2014-5646Sep 9, 2014
    risk 0.00cvss epss 0.00

    The AMC Security- Antivirus, Clean (aka com.iobit.mobilecare) application 4.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Page 2 of 2