Junglewise Threat Intelligence

CVE-2026-82670: IObit Uninstaller privilege escalation in IOCTL handler

CVE-2026-82670 · Severity: medium · CVSS 4.4 · Published 2026-08-31

Technologies: IObit Uninstaller. Vendors: IObit.

Executive brief

IObit Uninstaller is a popular Windows utility for removing software and system files. A vulnerability in its device driver (IUForceDelete.sys) allows a local attacker to manipulate system calls and execute operations with elevated privileges, potentially gaining administrative control of the system.

Technical details

The vulnerability exists in the IRP_MJ_DEVICE_CONTROL handler of the IUForceDelete.sys driver, which improperly manages privilege validation when processing IOCTL requests. An attacker with local system access can craft malicious IOCTL commands to bypass privilege checks and execute arbitrary operations with elevated permissions. The attack requires local access and does not involve remote network exploitation. The vendor was contacted prior to disclosure but did not provide a response or patch.

Affected products

  • IObit Uninstaller 15.5.0.11

Timeline

  • 2026-08-31: disclosed

References

Related threats