CVE-2026-82671
Received Received - Intake

Improper Privilege Management in IObit Unlocker 1.3.0.12

Vulnerability report for CVE-2026-82671, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation leads to improper privilege management. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
iobit unlocker 1.3.0.12
iobit iobit_unlocker 1.3.0.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in IObit Unlocker 1.3.0.12, specifically in the ZwTerminateProcess function within the IObitUnlocker.sys driver. It involves improper privilege management in the IRP_MJ_DEVICE_CONTROL handler, allowing local attackers to manipulate system processes.

Detection Guidance

This vulnerability requires local access to exploit and affects IObit Unlocker 1.3.0.12 through the IObitUnlocker.sys driver. Detection may involve checking for the presence of the vulnerable driver or unusual privilege escalation attempts. No specific commands are provided in the context.

Impact Analysis

An attacker with local access could exploit this to gain elevated privileges or disrupt system processes, potentially leading to unauthorized actions or system instability. The impact is limited to local attacks.

Compliance Impact

This vulnerability involves improper privilege management in IObit Unlocker 1.3.0.12, allowing local attacks. It does not directly impact GDPR or HIPAA compliance as it is not a data breach or privacy violation but could enable unauthorized system access, potentially leading to non-compliance if exploited to access sensitive data.

Mitigation Strategies

Immediately uninstall IObit Unlocker 1.3.0.12 to remove the vulnerable driver. Ensure no unauthorized processes are running with elevated privileges. Monitor system logs for suspicious activity related to the driver or privilege changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82671. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart