PT-2022-16488 · Iobit · Iobit Advanced Systemcare

Tomerpeled92

·

Published

2022-07-06

·

Updated

2022-07-14

·

CVE-2022-24138

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IOBit Advanced System Care versions 15
Description The issue allows low privilege users to gain code execution as a high privilege user by exploiting the "rwx" permissions for unprivileged users in the ProgramData folder. This is achieved by using SetOpLock to wait for CreateProcess and switching the genuine component with a malicious executable. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For IOBit Advanced System Care version 15, consider restricting access to the ProgramData folder to minimize the risk of exploitation. As a temporary workaround, avoid using the SetOpLock function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24138

Affected Products

Iobit Advanced Systemcare