Impact
A flaw exists in IObit Uninstaller version 15.5.0.11 where the IOCTL handler function IRP_MJ_DEVICE_CONTROL in the IUForceDelete.sys device driver fails to enforce correct privilege checks. When an attacker sends a crafted ioctl request, the driver may grant higher privileges than originally held. The issue manifests as a local privilege escalation vulnerability that could allow a user with local access to perform privileged actions that should be restricted.
Affected Systems
The affected product is IObit Uninstaller, specifically version 15.5.0.11. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and the EPSS score is not available, so the current exploitation probability is unknown. The vulnerability requires local access and relies on the driver’s improper privilege checks, meaning it is exploitable only by an authenticated local user who can interact with the device driver. The vendor has not been released a patch and the vulnerability is not listed in the CISA KEV catalog, implying no widespread or known exploit activity to date.
OpenCVE Enrichment