CVE-2021-21790: Medium severity iobit advanced systemcare vulnerability
An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read two bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this information disclosure vulnerability?
The vulnerability ID for this information disclosure vulnerability is CVE-2021-21790.
What is the affected software?
The affected software is IOBit Advanced SystemCare Ultimate version 14.2.0.220.
What is the severity of CVE-2021-21790?
The severity of CVE-2021-21790 is medium with a CVSS score of 5.5.
How does this vulnerability occur?
This vulnerability occurs due to the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specially crafted I/O request packet (IRP) that leads to privileged reads in the context of the driver, resulting in the disclosure of sensitive information.