CVE-2020-37223: IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation
IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to execute code with SYSTEM privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IObit Uninstallerto a version that resolves this vulnerability.Fixed in 9.5.0.15 - Configuration
Verify the IObitUnSvr service configuration uses a properly quoted executable path (or a space-free install path) so attackers cannot place a malicious executable named IObit.exe in C:\Program Files (x86)\IObit and restart the service for SYSTEM-level code execution.
IObitUnSvr service Unquoted service path = Ensure the service executable path is quoted (or moved to a path without spaces) to prevent exploitation via a malicious IObit.exe in C:\Program Files (x86)\IObit
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37223?
CVE-2020-37223 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2020-37223?
To fix CVE-2020-37223, update IObit Uninstaller to the latest version where the vulnerability has been addressed.
Which versions of IObit Uninstaller are affected by CVE-2020-37223?
CVE-2020-37223 specifically affects IObit Uninstaller version 9.5.0.15.
Can CVE-2020-37223 be exploited remotely?
No, CVE-2020-37223 requires local access to exploit the unquoted service path vulnerability.
What kind of attacks can exploit CVE-2020-37223?
CVE-2020-37223 can be exploited by local attackers to escalate privileges to the SYSTEM level.