CVE-2022-24140
IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.
Published:Jul 6, 2022
Last Modified:Nov 21, 2024
EPS:Jul 6, 2022
EPSS Score:0.00889
CVSS Score:6.6
Affected Products
Vendor
Product
Action
Vendor
Iobit
Product
Advanced System Care
Iobit
Advanced System Care
Vendor
Iobit
Product
Driver Booster
Iobit
Driver Booster
Vendor
Iobit
Product
Itop Screen Recorder
Iobit
Itop Screen Recorder
Vendor
Iobit
Product
Itop Screenshot
Iobit
Itop Screenshot
Vendor
Iobit
Product
Itop Vpn
Iobit
Itop Vpn
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
