Show filters
70 Total Results
Displaying 21-30 of 70
Sort by:
Attacker Value
Unknown

CVE-2022-37197

Disclosure Date: November 18, 2022 (last updated October 08, 2023)
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.
Attacker Value
Unknown

CVE-2022-37771

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.
Attacker Value
Unknown

CVE-2022-24141

Disclosure Date: July 06, 2022 (last updated October 07, 2023)
The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient().
Attacker Value
Unknown

CVE-2022-24140

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.
Attacker Value
Unknown

CVE-2022-24139

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named pipes, because of that during login the service will try to connect to the attacker which will lead to either escalation of privileges (through token manipulation and ImpersonateNamedPipeClient() ) from ADMIN -> SYSTEM or from Local ADMIN-> Domain ADMIN depending on the user and named pipe that is used.
Attacker Value
Unknown

CVE-2022-24138

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the genuine component with a malicious executable thus gaining code execution as a high privilege user (Low Privilege -> high integrity ADMIN).
Attacker Value
Unknown

CVE-2022-24562

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
Attacker Value
Unknown

CVE-2021-44968

Disclosure Date: February 18, 2022 (last updated February 23, 2025)
A Use after Free vulnerability exists in IOBit Advanced SystemCare 15 pro via requests sent in sequential order using the IOCTL driver codes, which could let a malicious user execute arbitrary code or a Denial of Service (system crash). IOCTL list: iobit_ioctl = [0x8001e01c, 0x8001e020, 0x8001e024, 0x8001e040,0x8001e044, 0x8001e048, 0x8001e04c, 0x8001e000, 0x8001e004, 0x8001e008, 0x8001e00c, 0x8001e010, 0x8001e014, 0x8001e018]
Attacker Value
Unknown

CVE-2021-21791

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read two bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.
Attacker Value
Unknown

CVE-2021-21785

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to a disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.