IObit Malware Fighter Unquoted Service Path Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in IObit Malware Fighter version 4.3.1. The issue arises from an unquoted service path in the 'IMFservice' and 'LiveUpdateSvc' services, allowing local attackers to escalate privileges. By inserting a malicious executable into the unquoted service path, attackers can execute code with LocalSystem privileges when the service is restarted or the system is rebooted.

Impact

Exploitation of this vulnerability allows for unauthorized privilege escalation, with executed code running under the LocalSystem account, which has extensive rights on the system.

Reproduction

To reproduce this vulnerability, first confirm that IObit Malware Fighter version 4.3.1 is installed on a Windows system. Next, insert a malicious executable into the unquoted service path of either the 'IMFservice' or 'LiveUpdateSvc' service. This can be done by placing the executable in the directory specified by the service's binary path. Once the executable is in place, restart the service or reboot the system. The malicious code will be executed with LocalSystem privileges, completing the exploitation of the vulnerability.

Added: Apr 4, 2026, 2:25 PM
Updated: Apr 4, 2026, 2:25 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
4.2
remediation
0.0
relevance
5.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.