CVE-2026-82670 PUBLISHED

IObit Uninstaller IOCTL IUForceDelete.sys IRP_MJ_DEVICE_CONTROL privileges management

Assigner: VulDB
Reserved: 30.08.2026 Published: 31.08.2026 Updated: 31.08.2026

A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a manipulation can lead to improper privilege management. The attack requires local access. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 4.8

Product Status

Vendor IObit
Product Uninstaller
Versions
  • Version 15.5.0.11 is affected

Credits

  • Element2023H (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Improper Privilege Management CWE
  • Incorrect Privilege Assignment CWE