PT-2021-14775 · Iobit · Iobit Advanced Systemcare Ultimate
Cory Duplantis
·
Published
2021-08-05
·
Updated
2022-07-29
·
CVE-2021-21790
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IOBit Advanced SystemCare Ultimate version 14.2.0.220
Description
An information disclosure issue exists in the way the driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver, resulting in sensitive information disclosure from the kernel. The
IN instruction can read two bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.Recommendations
For IOBit Advanced SystemCare Ultimate version 14.2.0.220, consider disabling the driver's handling of Privileged I/O read requests as a temporary workaround until a patch is available. Restrict access to sensitive device data to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iobit Advanced Systemcare Ultimate