PT-2021-14775 · Iobit · Iobit Advanced Systemcare Ultimate

Cory Duplantis

·

Published

2021-08-05

·

Updated

2022-07-29

·

CVE-2021-21790

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IOBit Advanced SystemCare Ultimate version 14.2.0.220
Description An information disclosure issue exists in the way the driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver, resulting in sensitive information disclosure from the kernel. The IN instruction can read two bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.
Recommendations For IOBit Advanced SystemCare Ultimate version 14.2.0.220, consider disabling the driver's handling of Privileged I/O read requests as a temporary workaround until a patch is available. Restrict access to sensitive device data to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21790

Affected Products

Iobit Advanced Systemcare Ultimate