A vulnerability was found in IObit Protected Folder up to 13.6.0.5 and classified as problematic. This issue affects the function 0x8001E000/0x8001E004 in the library IUProcessFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 23 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared I0bit
I0bit protected Folder
CPEs cpe:2.3:a:i0bit:protected_folder:*:*:*:*:*:*:*:*
Vendors & Products I0bit
I0bit protected Folder

Mon, 06 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in IObit Protected Folder up to 13.6.0.5 and classified as problematic. This issue affects the function 0x8001E000/0x8001E004 in the library IUProcessFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title IObit Protected Folder IOCTL IUProcessFilter.sys 0x8001E004 null pointer dereference
Weaknesses CWE-404
CWE-476
References
Metrics cvssV2_0

{'score': 4.6, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:C'}

cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-01-06T14:45:15.189Z

Reserved: 2025-01-04T08:52:54.244Z

Link: CVE-2025-0222

cve-icon Vulnrichment

Updated: 2025-01-06T14:45:06.820Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-05T16:15:05.217

Modified: 2025-01-23T17:46:40.140

Link: CVE-2025-0222

cve-icon Redhat

No data.