Junglewise Threat Intelligence

CVE-2020-37232: IObit Advanced SystemCare unquoted service path privilege escalation

CVE-2020-37232 · Severity: high · CVSS 7.8 · Published 2026-05-16

Vendors: IObit.

Executive brief

IObit Advanced SystemCare is a utility suite used to optimize and clean Windows computers. A security flaw in how the software starts its background service allows a local user with limited permissions to gain full administrative control of the system. This could lead to complete system takeover, data theft, or the installation of persistent malware that survives system reboots.

Technical details

The AdvancedSystemCareService13 service binary path is stored as an unquoted string containing spaces (e.g., C:\Program Files (x86)\Advanced SystemCare Pro\ASCService.exe). Due to how Windows handles service execution, a local attacker with write permissions to the system root or intermediate directories can place a malicious executable (such as C:\Program.exe) to be executed instead of the legitimate service. This occurs during service startup or system reboot, granting the attacker's code LocalSystem privileges. The vulnerability is classified as CWE-428.

Affected products

  • IObit Advanced SystemCare Service 13 13.0.0.157 and earlier

Timeline

  • 2020-11-10: disclosed: Initial discovery by researcher
  • 2020-11-16: other: Exploit published on Exploit-DB
  • 2026-05-16: advisory: NVD/VulnCheck advisory published

References