{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-12201","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-06-14T11:43:26.123Z","datePublished":"2026-06-15T00:30:08.901Z","dateUpdated":"2026-06-15T19:25:21.144Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-06-15T00:30:08.901Z"},"title":"IObit Malware Fighter DLL permission","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-275","lang":"en","description":"Permission Issues"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-266","lang":"en","description":"Incorrect Privilege Assignment"}]}],"affected":[{"vendor":"IObit","product":"Malware Fighter","versions":[{"version":"13.0","status":"affected"},{"version":"13.1","status":"affected"},{"version":"13.2.0","status":"affected"}],"cpes":["cpe:2.3:a:iobit:malware_fighter:*:*:*:*:*:*:*:*"],"modules":["DLL Handler"]}],"descriptions":[{"lang":"en","value":"A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler. This manipulation causes permission issues. The attack requires local access. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":4.8,"vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":5.3,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.3,"vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":4.3,"vectorString":"AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-06-14T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-06-14T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-06-14T13:48:29.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"nathan2 (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/370844","name":"VDB-370844 | IObit Malware Fighter DLL permission","tags":["vdb-entry"]},{"url":"https://vuldb.com/vuln/370844/cti","name":"VDB-370844 | CTI Indicators (IOB, IOC, TTP)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-12201","name":"CVE-2026-12201 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/829913","name":"Submit #829913 | IObit Malware Fighter 13.2.0 Insecure Permissions in Driver","tags":["third-party-advisory"]},{"url":"https://github.com/nasawyer7/IObitDriverav","tags":["related"]},{"url":"https://nathan2.com/posts/iobit/","tags":["exploit"]}],"tags":["x_freeware"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-15T16:32:10.193227Z","id":"CVE-2026-12201","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-15T19:25:21.144Z"}}]}}