IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to execute code with SYSTEM privileges.
References
Configurations
No configuration.
History
13 May 2026, 17:07
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 16:16
Updated : 2026-05-13 17:07
NVD link : CVE-2020-37223
Mitre link : CVE-2020-37223
CVE.ORG link : CVE-2020-37223
JSON object : View
Products Affected
No product.
CWE
CWE-428
Unquoted Search Path or Element
