CVE-2019-6494: Medium severity iobit malware fighter vulnerability
Published Apr 30, 2019
·Updated
IMFForceDelete.sys in IObit Malware Fighter 6.2 allows a low privileged user to send IOCTL 0x8016E000 along with a user defined string to a file; that file will be promptly deleted regardless of access controls.
Affected Software
1 affected component
IObit Malware Fighter=6.2
Event History
Apr 30, 2019
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2019-6494.
2
What is the severity of CVE-2019-6494?
The severity of CVE-2019-6494 is medium with a CVSS score of 6.5.
3
Which version of IObit Malware Fighter is affected by CVE-2019-6494?
Version 6.2 of IObit Malware Fighter is affected by CVE-2019-6494.
4
How can a low privileged user exploit CVE-2019-6494?
A low privileged user can send IOCTL 0x8016E000 along with a user defined string to a file, resulting in the prompt deletion of the file regardless of access controls.
5
Where can I find more information about CVE-2019-6494?
You can find more information about CVE-2019-6494 at this reference: [https://downwithup.github.io/CVEPosts.html](https://downwithup.github.io/CVEPosts.html)