CVE-2020-10234
The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device driver.
Does this matter?
Lower severity and a low EPSS score (3.77%). Track it; it rarely justifies an emergency change on its own.
Description
The AscRegistryFilter.sys kernel driver in IObit Advanced SystemCare 13.2 allows an unprivileged user to send an IOCTL to the device driver. If the user provides a NULL entry for the dwIoControlCode parameter, a kernel panic (aka BSOD) follows. The IOCTL codes can be found in the dispatch function: 0x8001E000, 0x8001E004, 0x8001E008, 0x8001E00C, 0x8001E010, 0x8001E014, 0x8001E020, 0x8001E024, 0x8001E040, 0x8001E044, and 0x8001E048. \DosDevices\AscRegistryFilter and \Device\AscRegistryFilter are affected.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.77% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- iobit/advanced systemcare
- Source
- cve@mitre.org
References
- https://github.com/FULLSHADE/Kernel-exploitsThird Party Advisory
- https://github.com/FULLSHADE/Kernel-exploits/tree/master/AscRegistryFilter.sysExploit, Third Party Advisory
- https://www.iobit.com/en/advancedsystemcarefree.phpProduct, Vendor Advisory
- https://github.com/FULLSHADE/Kernel-exploitsThird Party Advisory
- https://github.com/FULLSHADE/Kernel-exploits/tree/master/AscRegistryFilter.sysExploit, Third Party Advisory
- https://www.iobit.com/en/advancedsystemcarefree.phpProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.