Junglewise Threat Intelligence

CVE-2026-90485: IOBit Uninstaller null pointer dereference in IOCTL handler

CVE-2026-90485 · Severity: medium · CVSS 5.5 · Published 2026-09-12

Technologies: IObit Uninstaller. Vendors: IObit.

Executive brief

IOBit Uninstaller is a Windows utility that removes software applications. A flaw in the IOCTL dispatch handler of the IURegistryFilter.sys driver can cause the program to crash when handling specially crafted requests from a local user, disrupting system stability and availability.

Technical details

A null pointer dereference vulnerability exists in the function sub_11838 of IURegistryFilter.sys, a kernel-mode driver component responsible for handling I/O control (IOCTL) requests. The vulnerability is triggered when malformed IOCTL requests are sent to the driver, causing a null pointer dereference that crashes the affected process. The attack requires local access to the system and user-level privileges to invoke the vulnerable IOCTL handler. Exploitation results in denial of service through a system crash or driver crash. The vendor has not released a patch and did not respond to early disclosure notifications.

Affected products

  • IOBit Uninstaller 15.5.0.11

Timeline

  • 2026-09-12: disclosed

References

Related threats