CVE-2020-37223

IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to execute code with SYSTEM privileges.
Configurations

No configuration.

History

13 May 2026, 17:07

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-05-13 17:07


NVD link : CVE-2020-37223

Mitre link : CVE-2020-37223

CVE.ORG link : CVE-2020-37223


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element