Null Pointer Dereference Vulnerability in IObit Advanced SystemCare Ultimate
CVE-2024-12660
5.5MEDIUM
What is CVE-2024-12660?
CVE-2024-12660 identifies a critical null pointer dereference vulnerability found in the IObit Advanced SystemCare Ultimate software, affecting versions up to 17.0.0. This vulnerability resides in the IOCTL Handler within the library AscRegistryFilter.sys, specifically at the function identified by the code 0x8001E018. If exploited, this vulnerability could allow a local attacker to manipulate memory and potentially crash the application or execute arbitrary code. The exploit has been publicly disclosed, and despite early notifications to the vendor, IObit has not provided any response regarding a fix or mitigation strategy. Users of the affected versions are strongly advised to monitor for updates or consider alternatives.