IOBit Advanced SystemCare Free 13.5.0.263 allows local users to gain privileges for file deletion by manipulating the Clean & Optimize feature with an NTFS junction and an Object Manager symbolic link.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://daniels-it-blog.blogspot.com/2020/06/arbitrary-file-deletion-in-iobit.html | third party advisory exploit |
https://github.com/Daniel-itsec/AdvancedSystemCare | third party advisory exploit |