CVE-2020-14974

HIGH

IOBit Unlocker 1.1.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-14974. PoCs published by Aterror2be.

AI-analyzed exploit summary This PoC demonstrates a local privilege escalation (LPE) exploit for CVE-2020-14974, targeting IObit Unlocker's driver vulnerability. It interacts with the vulnerable driver to perform file operations with elevated privileges.

Description

The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124.

Exploits (1)

nomisec WORKING POC 7 stars
by Aterror2be · poc
https://github.com/Aterror2be/CVE-2020-14974

This PoC demonstrates a local privilege escalation (LPE) exploit for CVE-2020-14974, targeting IObit Unlocker's driver vulnerability. It interacts with the vulnerable driver to perform file operations with elevated privileges.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: IObit Unlocker (version not specified)
No auth needed
Prerequisites: Local access to the target system · IObit Unlocker installed with vulnerable driver
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.iobit.com/en/iobit-unlocker.php
Exploit, Third Party Advisory x_refsource_misc
https://theevilbit.github.io/posts/

Scores

CVSS v3 7.1
EPSS 0.0090
EPSS Percentile 55.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

Status published
Products (1)
iobit/iobit_unlocker 1.1.2
Published Jun 23, 2020
Tracked Since Feb 18, 2026