PT-2022-16488 · Iobit · Iobit Advanced Systemcare
Tomerpeled92
·
Published
2022-07-06
·
Updated
2022-07-14
·
CVE-2022-24138
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IOBit Advanced System Care versions 15
Description
The issue allows low privilege users to gain code execution as a high privilege user by exploiting the "rwx" permissions for unprivileged users in the ProgramData folder. This is achieved by using SetOpLock to wait for CreateProcess and switching the genuine component with a malicious executable. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
For IOBit Advanced System Care version 15, consider restricting access to the ProgramData folder to minimize the risk of exploitation. As a temporary workaround, avoid using the SetOpLock function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iobit Advanced Systemcare