Executive brief
A security flaw in IObit Malware Fighter, a popular antivirus and anti-malware tool, allows an attacker with local access to the computer to gain elevated permissions. By exploiting how the software handles certain system files, an attacker can delete arbitrary files or execute unauthorized code with high-level system privileges. This could lead to a complete takeover of the affected computer or the disabling of security protections.
Technical details
A local privilege escalation vulnerability exists in IObit Malware Fighter up to version 13.2.0 due to incorrect privilege assignment (CWE-266) and insecure DLL handling. The flaw involves a 'DLL Handler' component that can be manipulated by a local user with low privileges to delete arbitrary files or perform DLL sideloading. Specifically, an attacker can replace or spoof 'ProductNews2.dll' in the application directory or search path to execute code with high integrity. This vulnerability represents a bypass of a previous patch attempt by the vendor. As of the advisory date, the vendor has not released a fix, and functional exploit code is publicly available.
Affected products
- IObit Malware Fighter up to 13.2.0
Timeline
- 2026-03-11: other: Exploit code published on GitHub
- 2026-06-15: disclosed: Vulnerability disclosed and CVE assigned