CVE-2022-37771

MEDIUM

Iobit Malware Fighter - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable.

References (2)

Core 2
Core References

Scores

CVSS v3 6.7
EPSS 0.0011
EPSS Percentile 28.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
iobit/malware_fighter 9.2
Published Sep 06, 2022
Tracked Since Feb 18, 2026