PatchSiren

IObit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IObit CVE published 2026-08-31

CVE-2026-82671

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T10:16:50.603Z and has not been modified since then. IObit Unlocker 1.3.0.12 has a vulnerability affecting the ZwTerminateProcess function in IObitUnlocker.sys, leading to improper privilege management; local attack vector. This vulnerability requires local access to be exploited and has been publ [truncated]

MEDIUM IObit CVE published 2026-08-31

CVE-2026-82670

The IObit Uninstaller 15.5.0.11 contains a flaw in the IUForceDelete.sys library's IOCTL Handler, leading to improper privilege management. This vulnerability requires local access for exploitation and may allow attackers to gain elevated privileges. System administrators and users of IObit Uninstaller 15.5.0.11 should verify and apply patches if available to prevent potential local privilege escalation a [truncated]

LOW IObit CVE published 2026-06-15

CVE-2026-12201

A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

HIGH Iobit CVE published 2026-04-04

CVE-2016-20059

CVE-2016-20059 is a high-severity vulnerability in IObit Malware Fighter 4.3.1. The issue arises from an unquoted service path in the IMFservice and LiveUpdateSvc services, which can be exploited by local attackers to escalate privileges. By inserting a malicious executable file into the unquoted service path, attackers can trigger privilege escalation when the service restarts or the system reboots, exec [truncated]