CVE-2026-7832 PUBLISHED

IObit Advanced SystemCare Service ASC.exe symlink

Assigner: VulDB
Reserved: 05.05.2026 Published: 05.05.2026 Updated: 05.05.2026

A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attacking locally is a requirement. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 7.3

Product Status

Vendor IObit
Product Advanced SystemCare
Versions
  • Version 19 is affected

Credits

  • usernameone101 (VulDB User) reporter

References

Problem Types

  • Symlink Following CWE
  • Link Following CWE