Impact
IOBit Uninstaller version 15.5.0.11 contains a null pointer dereference in the kernel driver IURegistryFilter.sys, within the function sub_11838 of the IOCTL Dispatch Handler. The vulnerability is triggered by a manipulation of the IOCTL interface, though the exact request is not outlined in the CVE text; the CVE indicates that a crafted message can lead to the dereference. The null pointer dereference occurs in kernel mode, which typically causes a system crash, thereby denying service to all local users and administrators. The flaw requires local access and an exploit has already been published, so any privileged local user can provoke the crash. The impact is loss of availability, and if the crash occurs while critical services are running it can lead to data loss or corruption.
Affected Systems
The affected product is IOBit Uninstaller version 15.5.0.11. The same IURegistryFilter.sys driver is distributed unchanged to other IObit families, so those products are also susceptible. No other vendors or product versions are listed by the CNA.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not catalogued in CISA’s KEV list, but an exploit is publicly available, making the risk real for anyone who can run the Uninstaller with local privileges. Local attackers can trigger a kernel crash that brings the system down; thus the risk is primarily availability, though a crash could also lead to data loss.
OpenCVE Enrichment