Impact
A flaw in IObit Unlocker 1.3.0.12 allows a local attacker to abuse the ZwTerminateProcess call from the IObitUnlocker.sys driver, resulting in improper privilege management that can elevate the attacker’s rights. The vulnerability arises from an error in the IRP_MJ_DEVICE_CONTROL handler that fails to enforce correct access controls when terminating processes. Because of this, a local user could potentially gain higher privileges, enabling unauthorized access to system resources, modification of data, or disruption of services.
Affected Systems
IObit Unlocker, version 1.3.0.12, a desktop utility for unlocking files and folders. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, while the EPSS score is not available and KEV does not list the vulnerability, suggesting limited widespread exploitation. Attackers must first establish a local presence, which reduces the likelihood of exploitation compared to remote vectors. However, the local privilege escalation potential remains significant for systems with vulnerable versions still installed, and the lack of an official vendor patch increases the risk for exposed environments.
OpenCVE Enrichment