Executive brief
IObit Advanced SystemCare is a utility suite used to optimize and clean Windows computers. A security flaw in how the software starts its background service allows a local user with limited permissions to gain full administrative control of the system. This could lead to complete system takeover, data theft, or the installation of persistent malware that survives system reboots.
Technical details
The AdvancedSystemCareService13 service binary path is stored as an unquoted string containing spaces (e.g., C:\Program Files (x86)\Advanced SystemCare Pro\ASCService.exe). Due to how Windows handles service execution, a local attacker with write permissions to the system root or intermediate directories can place a malicious executable (such as C:\Program.exe) to be executed instead of the legitimate service. This occurs during service startup or system reboot, granting the attacker's code LocalSystem privileges. The vulnerability is classified as CWE-428.
Affected products
- IObit Advanced SystemCare Service 13 13.0.0.157 and earlier
Timeline
- 2020-11-10: disclosed: Initial discovery by researcher
- 2020-11-16: other: Exploit published on Exploit-DB
- 2026-05-16: advisory: NVD/VulnCheck advisory published