CVE-2021-21786
07.07.2021, 17:15
A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to increased privileges. An attacker can send a malicious IRP to trigger this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
iobit | advanced_systemcare_ultimate | 14.2.0.220 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-782 - Exposed IOCTL with Insufficient Access ControlThe software implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.