A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 19 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Iobit
Iobit advanced Systemcare Ultimate
CPEs cpe:2.3:a:iobit:advanced_systemcare_ultimate:*:*:*:*:*:*:*:*
Vendors & Products Iobit
Iobit advanced Systemcare Ultimate

Mon, 16 Dec 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Dec 2024 18:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title IObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E040 null pointer dereference
Weaknesses CWE-404
CWE-476
References
Metrics cvssV2_0

{'score': 4.6, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:C'}

cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-12-16T18:31:06.971Z

Updated: 2024-12-16T19:07:08.015Z

Reserved: 2024-12-16T08:36:58.081Z

Link: CVE-2024-12662

cve-icon Vulnrichment

Updated: 2024-12-16T19:07:00.438Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-16T19:15:07.027

Modified: 2024-12-19T14:45:43.547

Link: CVE-2024-12662

cve-icon Redhat

No data.