CVE-2026-82671: IObit Unlocker IRP_MJ_DEVICE_CONTROL IObitUnlocker.sys ZwTerminateProcess privileges management
A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRPMJDEVICECONTROL Handler. The manipulation leads to improper privilege management. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running IObit Unlocker 1.3.0.12 are affected. Exploitation requires local access and high privileges, so it is not a remote attack vector.
What access does an attacker need to exploit it?
The CVSS vector indicates local access, low attack complexity, no user interaction, and high privileges required. The issue is in the IRP_MJ_DEVICE_CONTROL handler of IObitUnlocker.sys and involves ZwTerminateProcess privilege management.
Is a vendor fix available?
The available information does not identify a fix or patched version. The vendor was contacted during disclosure but did not respond.