Null Pointer Dereference in IOBit Uninstaller 15.5.0.11
CVE-2026-90485

6.8MEDIUM

Key Information:

Vendor

Iobit

Vendor
CVE Published:
12 September 2026

What is CVE-2026-90485?

A null pointer dereference vulnerability has been identified in IOBit Uninstaller version 15.5.0.11. This issue resides in the function sub_11838 of the IURegistryFilter.sys file, specifically within the component that handles IOCTL dispatch. When exploited, this flaw can lead to system instability and potential unauthorized access, requiring local access for successful exploitation. The IURegistryFilter.sys component is shared across various IOBit products, increasing the risk of widespread impact. Despite early communication regarding this vulnerability, the vendor has not provided any updates or responses.

Affected Version(s)

Uninstaller 15.5.0.11

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bigcat (VulDB User)
VulDB CNA Team
.