PatchSiren

Iobit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW IObit CVE published 2026-06-15

CVE-2026-12201

A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

HIGH Iobit CVE published 2026-04-04

CVE-2016-20059

CVE-2016-20059 is a high-severity vulnerability in IObit Malware Fighter 4.3.1. The issue arises from an unquoted service path in the IMFservice and LiveUpdateSvc services, which can be exploited by local attackers to escalate privileges. By inserting a malicious executable file into the unquoted service path, attackers can trigger privilege escalation when the service restarts or the system reboots, exec [truncated]