Improper Privilege Management in IObit Uninstaller by IObit
CVE-2026-82670

4.8MEDIUM

Key Information:

Vendor

Iobit

Vendor
CVE Published:
31 August 2026

What is CVE-2026-82670?

A vulnerability in IObit Uninstaller 15.5.0.11 has been identified, associated with the IRP_MJ_DEVICE_CONTROL function in the IUForceDelete.sys library. This flaw allows an attacker with local access to manipulate the system, leading to insufficient privilege management. Notably, attempts to disclose this issue to the vendor went unanswered, leaving users at potential risk. Proper security measures should be considered to mitigate the impact of this vulnerability.

Affected Version(s)

Uninstaller 15.5.0.11

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Element2023H (VulDB User)
VulDB CNA Team
.