PT-2023-2361 · Iobit · Iobit Malware Fighter

Zeze7W

·

Published

2023-03-26

·

Updated

2024-05-17

·

CVE-2023-1645

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions IObit Malware Fighter version 9.4.0.776
Description The issue is related to the incorrect cleanup or release of resources in the IMFCameraProtect.sys component of IObit Malware Fighter. This can lead to a denial of service when exploited. The attack must be approached locally and affects the function 0x8018E008 in the library IMFCameraProtect.sys of the component IOCTL Handler.
Recommendations For IObit Malware Fighter version 9.4.0.776, consider disabling the 0x8018E008 function in the IMFCameraProtect.sys library as a temporary workaround until a patch is available. Restrict access to the IOCTL Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2023-02136
CVE-2023-1645

Affected Products

Iobit Malware Fighter