Improper Privilege Management in IObit Unlocker by IObit
CVE-2026-82671

4.6MEDIUM

Key Information:

Vendor

Iobit

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82671?

A vulnerability exists in IObit Unlocker version 1.3.0.12 due to improper privilege management within the ZwTerminateProcess function of the IObitUnlocker.sys library. This flaw can potentially allow local attackers to manipulate privilege levels, resulting in unauthorized access or control over system processes. The vendor has been notified about this issue but has not provided a response. Users of this software should be aware of this vulnerability and take necessary precautions.

Affected Version(s)

Unlocker 1.3.0.12

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Element2023H (VulDB User)
VulDB CNA Team
.