Executive brief
IOBit Uninstaller is a Windows utility that removes software applications. A flaw in the IOCTL dispatch handler of the IURegistryFilter.sys driver can cause the program to crash when handling specially crafted requests from a local user, disrupting system stability and availability.
Technical details
A null pointer dereference vulnerability exists in the function sub_11838 of IURegistryFilter.sys, a kernel-mode driver component responsible for handling I/O control (IOCTL) requests. The vulnerability is triggered when malformed IOCTL requests are sent to the driver, causing a null pointer dereference that crashes the affected process. The attack requires local access to the system and user-level privileges to invoke the vulnerable IOCTL handler. Exploitation results in denial of service through a system crash or driver crash. The vendor has not released a patch and did not respond to early disclosure notifications.
Affected products
- IOBit Uninstaller 15.5.0.11
Timeline
- 2026-09-12: disclosed