Permission Issue in IObit Malware Fighter by IObit
CVE-2026-12201
Key Information:
- Vendor
Iobit
- Status
- Vendor
- CVE Published:
- 15 June 2026
Badges
What is CVE-2026-12201?
A security flaw exists in IObit Malware Fighter versions up to 13.2.0, specifically related to its DLL Handler component. This vulnerability introduces permission issues that can be exploited by attackers with local access to the system. The exploit has already been made public, which raises concerns over the potential for misuse. Despite early communication attempts, the vendor has not responded to the disclosure.
Affected Version(s)
Malware Fighter 13.0
Malware Fighter 13.1
Malware Fighter 13.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
