Null Pointer Dereference Vulnerability in IObit Advanced SystemCare Ultimate
CVE-2024-12659
5.5MEDIUM
What is CVE-2024-12659?
CVE-2024-12659 is a high-risk vulnerability discovered in IObit Advanced SystemCare Ultimate, specifically in the IOCTL Handler of the AscRegistryFilter.sys library. This vulnerability allows an attacker to exploit a null pointer dereference through function code 0x8001E004. Such exploitation can lead to system instability and may grant an attacker increased privileges. Local access is required for an exploit to be initiated, enhancing the risk to users who may be unaware of the vulnerability. IObit has been notified of this issue, but no response has been received, indicating potential risks to user systems.