Privilege Escalation Vulnerability in IOBit Advanced SystemCare by IOBit
CVE-2021-21788
8.8HIGH
What is CVE-2021-21788?
A vulnerability in IOBit Advanced SystemCare Ultimate version 14.2.0.220 allows local attackers to escalate privileges. This occurs due to improper handling of privileged I/O write requests within the driver. Specifically, during the execution of IOCTL 0x9c40a0dc, attackers can manipulate the input buffer to gain elevated access, potentially allowing them to write arbitrary bytes to specified I/O device ports. This flaw opens the door for unauthorized access and exploitation by unprivileged users, underscoring the need for prompt security measures.
Affected Version(s)
Iobit IOBit Advanced SystemCare Ultimate 14.2.0.220
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
CVSS V3.0
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
