CVE detail
CVE-2021-21785 — CVE-2021-21785
Published 2021-08-05 · Modified 2026-06-17 · Vendor iobit · Product advanced_systemcare_ultimate · Source nvd
MEDIUM
severity
CVSS-derived band
0.0034
EPSS probability
exploitation probability, 30d
26.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to a disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References