CVE-2022-37771
MEDIUM 6.7EPSS 0.4%
IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.
- CVSS v3.1
- 6.7 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.39% chance of exploitation in the next 30 days, 32th percentile
- Published
- 2022-09-06
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- https://packetstormsecurity.com/files/167913/IObit-Malware-Fighter-9.2-Tampering-Privileg…
- https://mrvar0x.com/2022/08/02/multiple-endpoints-security-tampering-exploit/