PT-2026-40624 · Iobit · Iobit Uninstaller

Gobinathan L

·

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2020-37223

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:Program Files (x86)IObit directory and restart the service to execute code with SYSTEM privileges.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-37223

Affected Products

Iobit Uninstaller