VulnSea

iobit has 8 CVEs on record between 2022 and 2026. 1 was published in the last 90 days. The median CVSS is 7.8 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: advanced_system_care (3), Uninstaller (1), advanced_systemcare (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
1 prev 2

Products

  • advanced_system_care 3
  • Uninstaller 1
  • advanced_systemcare 1
  • iotransfer 1
  • itop_vpn 1
  • malware_fighter 1
8
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

iobit vulnerabilities

CVEs affecting iobit, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-90485Medium· 5.5PoC
1w ago

A flaw has been found in IOBit Uninstaller 15.5.0.11

A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attac…

TwilightIOBit · UninstallerEPSS 0.16%via NVD
CVE-2016-20059High· 7.8
5mo ago

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted…

Twilightiobit · malware_fighterEPSS 0.18%via NVD
CVE-2016-20055High· 7.8
5mo ago

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service pat…

Twilightiobit · advanced_system_careEPSS 0.18%via NVD
CVE-2022-24141Medium· 5.4
4y ago

The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop

The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connectio…

Sunlitiobit · itop_vpnEPSS 0.57%via NVD
CVE-2022-24140Medium· 6.6
4y ago

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the product…

Sunlitiobit · advanced_system_careEPSS 0.72%via NVD
CVE-2022-24139High· 7.8
4y ago

In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes

In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named…

Twilightiobit · advanced_system_careEPSS 0.37%via NVD
CVE-2022-24138High· 7.8
4y ago

IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users

IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unprivileged users. Low privilege users can use SetOpLock to…

Twilightiobit · advanced_systemcareEPSS 0.58%via NVD
CVE-2022-24562Critical· 9.8PoC
4y ago

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in da…

In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in da…

Abyssaliobit · iotransferEPSS 54%via NVD
iobit vulnerabilities (CVEs) · VulnSea