CVE-2020-14974

HIGH

IOBit Unlocker 1.1.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124.

Exploits (1)

nomisec WORKING POC 7 stars
by Aterror2be · poc
https://github.com/Aterror2be/CVE-2020-14974

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.iobit.com/en/iobit-unlocker.php
Exploit, Third Party Advisory x_refsource_misc
https://theevilbit.github.io/posts/

Scores

CVSS v3 7.1
EPSS 0.0215
EPSS Percentile 84.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

Status published
Products (1)
iobit/iobit_unlocker 1.1.2
Published Jun 23, 2020
Tracked Since Feb 18, 2026