CVE-2022-24138
- EPSS 0.4%
- Veröffentlicht 06.07.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:53
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for Cre...
CVE-2021-44968
- EPSS 0.08%
- Veröffentlicht 18.02.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:31:45
A Use after Free vulnerability exists in IOBit Advanced SystemCare 15 pro via requests sent in sequential order using the IOCTL driver codes, which could let a malicious user execute arbitrary code or a Denial of Service (system crash). IOCTL list: i...
CVE-2020-10234
- EPSS 0.51%
- Veröffentlicht 05.02.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:01
The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device driver. If the user provides a NULL entry for the dwIoControlCode parameter, a kernel panic (aka BSOD) follows. The I...
CVE-2020-14990
- EPSS 0.08%
- Veröffentlicht 22.06.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:04:35
IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.
CVE-2018-16711
- EPSS 8.72%
- Veröffentlicht 26.09.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:12
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content. The driver's subroutine will e...
CVE-2018-16712
- EPSS 0.92%
- Veröffentlicht 26.09.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:12
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send a specially crafted IOCTL 0x9C406104 to read physical memory.
CVE-2018-16713
- EPSS 6.15%
- Veröffentlicht 26.09.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:12
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will e...