An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read two bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1255 | third party advisory exploit |