Null Pointer Dereference Vulnerability in IObit Advanced SystemCare Ultimate
CVE-2024-12660

5.5MEDIUM

Key Information:

Vendor

IObit

Vendor
CVE Published:
16 December 2024

What is CVE-2024-12660?

CVE-2024-12660 identifies a critical null pointer dereference vulnerability found in the IObit Advanced SystemCare Ultimate software, affecting versions up to 17.0.0. This vulnerability resides in the IOCTL Handler within the library AscRegistryFilter.sys, specifically at the function identified by the code 0x8001E018. If exploited, this vulnerability could allow a local attacker to manipulate memory and potentially crash the application or execute arbitrary code. The exploit has been publicly disclosed, and despite early notifications to the vendor, IObit has not provided any response regarding a fix or mitigation strategy. Users of the affected versions are strongly advised to monitor for updates or consider alternatives.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.