IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to wait for CreateProcess and switch the genuine component with a malicious executable thus gaining code execution as a high privilege user (Low Privilege -> high integrity ADMIN).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-07-06T12:41:26
Updated: 2024-08-03T04:07:01.457Z
Reserved: 2022-01-31T00:00:00
Link: CVE-2022-24138
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-06T13:15:09.230
Modified: 2024-11-21T06:49:53.140
Link: CVE-2022-24138
Redhat
No data.