Privilege Escalation Vulnerability in IOBit Advanced SystemCare by IOBit
CVE-2021-21788

8.8HIGH

Key Information:

Vendor

Iobit

Status
Vendor
CVE Published:
7 July 2021

What is CVE-2021-21788?

A vulnerability in IOBit Advanced SystemCare Ultimate version 14.2.0.220 allows local attackers to escalate privileges. This occurs due to improper handling of privileged I/O write requests within the driver. Specifically, during the execution of IOCTL 0x9c40a0dc, attackers can manipulate the input buffer to gain elevated access, potentially allowing them to write arbitrary bytes to specified I/O device ports. This flaw opens the door for unauthorized access and exploitation by unprivileged users, underscoring the need for prompt security measures.

Affected Version(s)

Iobit IOBit Advanced SystemCare Ultimate 14.2.0.220

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.