Uncontrolled Search Path Vulnerability in IObit Driver Booster by IObit
CVE-2024-7325

7.8HIGH

Key Information:

Vendor

Iobit

Vendor
CVE Published:
31 July 2024

What is CVE-2024-7325?

A vulnerability identified in IObit Driver Booster version 11.0.0.0 involves an uncontrolled search path in the component BPL Handler, specifically affecting the library VCL120.BPL. Local exploitation is necessary to manipulate this functionality, which could pose significant risks to system integrity if leveraged by an attacker. Despite early notification to the vendor regarding this critical issue, there has been no response to address the potential risks associated with this vulnerability. Users are advised to exercise caution and monitor for any updates or patches.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.