6.8

CVE-2020-10234

Exploit
The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device driver. If the user provides a NULL entry for the dwIoControlCode parameter, a kernel panic (aka BSOD) follows. The IOCTL codes can be found in the dispatch function: 0x8001E000, 0x8001E004, 0x8001E008, 0x8001E00C, 0x8001E010, 0x8001E014, 0x8001E020, 0x8001E024, 0x8001E040, 0x8001E044, and 0x8001E048. \DosDevices\AscRegistryFilter and \Device\AscRegistryFilter are affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IobitAdvanced Systemcare Version13.2 SwPlatformwindows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.78% 0.885
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 6.8 8 6.9
AV:N/AC:L/Au:S/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/FULLSHADE/Kernel-exploits
Third Party Advisory
https://github.com/FULLSHADE/Kernel-exploits/tree/master/AscRegistryFilter.sys
Third Party Advisory
Exploit
https://www.iobit.com/en/advancedsystemcarefree.php
Vendor Advisory
Product