Null Pointer Dereference Vulnerability in IObit Advanced SystemCare Ultimate
CVE-2024-12657
5.5MEDIUM
What is CVE-2024-12657?
A significant vulnerability identified in IObit Advanced SystemCare Ultimate, specifically impacting versions up to 17.0.0. This vulnerability involves a null pointer dereference within the IOCTL Handler function (0x8001E000) located in the AscRegistryFilter.sys library. Exploitation requires local access, making it critical for users to apply security measures immediately to mitigate potential threats, especially since the vulnerability has been publicly disclosed and may already be exploited. Despite early notification, IObit has not responded regarding this security issue, raising concerns about user safety.