CVE-2026-82670
Received Received - Intake

Privilege Escalation in IObit Uninstaller via IOCTL Handler

Vulnerability report for CVE-2026-82670, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a manipulation can lead to improper privilege management. The attack requires local access. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
iobit iobit_uninstaller 15.5.0.11

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in IObit Uninstaller 15.5.0.11 affecting the IRP_MJ_DEVICE_CONTROL function in the IUForceDelete.sys library. It involves improper privilege management due to a manipulation in the IOCTL Handler. The attack requires local access to exploit.

Detection Guidance

This vulnerability requires local access and involves the IOCTL handler in IUForceDelete.sys. Detection may involve checking for suspicious processes or drivers related to IObit Uninstaller 15.5.0.11. Use commands like 'sc query IUForceDelete' or 'driverquery | findstr IObit' to inspect drivers. Monitor for unexpected privilege escalation attempts or unusual IOCTL calls.

Impact Analysis

An attacker with local access could exploit this flaw to gain elevated privileges on the affected system. This may allow unauthorized changes, data access, or control over the system depending on the attacker's goals.

Compliance Impact

The vulnerability involves improper privilege management due to a flaw in IObit Uninstaller 15.5.0.11, requiring local access. This could potentially lead to unauthorized privilege escalation, which may impact compliance with standards like GDPR or HIPAA by compromising data integrity or confidentiality. However, specific compliance impacts are not detailed in the provided context.

Mitigation Strategies

Immediately uninstall IObit Uninstaller 15.5.0.11 from your system. Disable or remove the IUForceDelete.sys driver if present. Restrict local access to untrusted users. Apply vendor patches if available in the future. Monitor system logs for suspicious activity related to privilege management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82670. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart