Description
IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to execute code with SYSTEM privileges.
Problem types
Unquoted Search Path or Element
Product status
Credits
Gobinathan L
References
www.exploit-db.com/exploits/48543 (ExploitDB-48543)
www.iobit.com (Official Product Homepage)
www.iobit.com/en/advanceduninstaller.php (Product Reference)
www.vulncheck.com/...uoted-service-path-privilege-escalation (VulnCheck Advisory: IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation)