Junglewise Threat Intelligence

CVE-2026-82671: IObit Unlocker privilege escalation in device control handler

CVE-2026-82671 · Severity: low · CVSS 3.4 · Published 2026-08-31

Vendors: IObit.

Executive brief

IObit Unlocker is a utility used to unlock and remove files that cannot be deleted normally by Windows. A vulnerability in the driver's device control handler allows a local attacker to manipulate privileged system functions, potentially enabling unauthorized file deletion or system interference that would normally be restricted.

Technical details

A privilege management flaw exists in the IRP_MJ_DEVICE_CONTROL handler of the IObitUnlocker.sys kernel driver. The vulnerability affects the ZwTerminateProcess function implementation, allowing improper handling of process termination requests. The attack requires local system access and interaction with the vulnerable driver through device I/O control operations. An authenticated local attacker can exploit this to perform privileged operations that bypass normal security restrictions. The vendor was contacted early but did not provide a response or patch.

Affected products

  • IObit Unlocker 1.3.0.12

Timeline

  • 2026-08-31: disclosed

References