← back
CVE-2023-1642

IObit Malware Fighter IOCTL ObCallbackProcess.sys 0x222040 denial of service

CVSS 5.5 MEDIUMEPSS 0.3%CWE-404
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability, which was classified as problematic, was found in IObit Malware Fighter 9.4.0.776. Affected is the function 0x222034/0x222038/0x22203C/0x222040 in the library ObCallbackProcess.sys of the component IOCTL Handler. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. VDB-224022 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
IObit · Malware Fighter

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →