Vulnerability Spotlight: Information disclosure, privilege escalation vulnerabilities in IOBit Advanced SystemCare Ultimate
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-21792 | An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read four bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2021-21787 | A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0d8, the first dword passed in the input buffer is the device port to write to and the byte at offset 4 is the value to write via the OUT instruction. The OUT instruction can write one byte to the given I/O device port, potentially leading to escalated privileges of unprivileged users. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — |
Full article246 words · extracted from blog.talosintelligence.com · click to collapse
Wednesday, July 7, 2021 16:41
Cory Duplantis of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered multiple vulnerabilities in IOBit Advanced SystemCare Ultimate.
IOBit Advanced SystemCare Ultimate is a system optimizer that promises to remove unwanted files and application from PCs to improve performance. The software allows users to view services running on their computer, processes that are using a large amount of memory and updates for other software. These vulnerabilities all exist in a monitoring driver in the software.
TALOS-2021-1255 (CVE-2021-21790 - CVE-2021-21792) and TALOS-2021-1252 (CVE-2021-21785) are information disclosure vulnerabilities that an attacker could trigger by tricking the user into opening a specially crafted I/O request packet (IRP).
An attacker could use the same method to also exploit TALOS-2021-1254 (CVE-2021-21787 - CVE-2021-21789) and TALOS-2021-1253 (CVE-2021-21786). These vulnerabilities could allow unprivileged users to obtain escalated privileges.
Talos is disclosing these vulnerabilities despite no official update from IOBit inside the 90-day deadline, as outlined in Cisco’s vulnerability disclosure policy.
Users are encouraged to update these affected products as soon as possible: IOBit Advanced SystemCare Ultimate, version 14.2.0.220. Talos tested and confirmed these versions of Advanced SystemCare Ultimate could be exploited by this vulnerability.

The following SNORTⓇ rules will detect exploitation attempts against this vulnerability: 57189 and 57190. Additional rules may be released in the future and current rules are subject to change, pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vuln-spotlight-iobit0-/