Iobit develops system optimization and security utilities for Windows endpoints, including products such as Advanced SystemCare Ultimate, Malware Fighter, and Iobit Unlocker that operate at or below the OS level to manage performance and protect against threats. The vendor's vulnerability profile reflects the inherent complexity of kernel-adjacent and file-system manipulation code: recurring weakness classes center on improper input validation, resource management flaws, and insufficient access controls on privileged I/O operations, which are characteristic risks in low-level system tools. A meaningful share of the vendor's disclosures reach serious severity, and the exposure pattern suggests these products attract sustained security attention from researchers and the defensive community. Defenders deploying these utilities should prioritize timely patching of the system-level components and monitor for elevated-privilege exploitation vectors. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iobit over time
Signals from CVEs in this vendor scope (72 CVEs).
72 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24562CRITICAL In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin pri | Jun 16, 2022 | 9.8 | 74 | NO | YES |
CVE-2022-37197HIGH IOBit IOTransfer V4 is vulnerable to Unquoted Service Path. | Nov 18, 2022 | 7.8 | 36 | NO | YES |
CVE-2016-20055HIGH IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Atta | Apr 4, 2026 | 7.8 | 29 | NO | NO |
CVE-2022-24138HIGH IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramData folder, ProgramData folder has "rwx" permissions for unp | Jul 6, 2022 | 7.8 | 28 | NO | NO |
CVE-2018-9000HIGH In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact becaus | Mar 25, 2018 | 7.8 | 28 | NO | NO |
CVE-2016-20059HIGH IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attacke | Apr 4, 2026 | 7.8 | 27 | NO | NO |
CVE-2022-24139HIGH In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService | Jul 6, 2022 | 7.8 | 27 | NO | NO |
CVE-2021-21787HIGH A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0d8, the firs | Jul 7, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-21789HIGH A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0e0, the firs | Jul 7, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-21788HIGH A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0dc, the firs | Jul 7, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (72 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iobit.
Media articles that mention a CVE ID that affects a product developed by Iobit — matched by CVE ID, not by vendor name.