An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read four bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.
References
Link | Resource |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1255 | Exploit Third Party Advisory |
Configurations
History
11 Aug 2021, 20:04
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
References | (MISC) https://talosintelligence.com/vulnerability_reports/TALOS-2021-1255 - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 5.5 |
CPE | cpe:2.3:a:iobit:advanced_systemcare_ultimate:14.2.0.220:*:*:*:*:*:*:* |
05 Aug 2021, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-05 21:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-21792
Mitre link : CVE-2021-21792
CVE.ORG link : CVE-2021-21792
JSON object : View
Products Affected
iobit
- advanced_systemcare_ultimate
CWE