← Vulnerability feed

Vulnerability record · CVE-2022-24140 · published 6 July 2022

CVE-2022-24140: Iobit advanced system care download of code without integrity check vulnerability

Iobit · Advanced System Care

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.

6.6 CVSS 3.1 Medium EPSS 0.71% · top 48.3% CWE-494 · Download of code without integrity check
6.6CVSS 3.1 base score, v2 6.0
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
9 Jul 2026Last modified by NVD

Description

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/tomerpeled92/CVE/ Third Party Advisory
https://github.com/tomerpeled92/CVE/ Third Party Advisory

Track CVE-2022-24140 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2016-20055Iobit advanced system care unquoted search path vulnerabilityIObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attacke…EPSS 0.18%8.5CVE-2024-7325Iobit driver booster uncontrolled search path element vulnerabilityA vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is some unknown functionality in th…EPSS 0.23%7.8CVE-2022-24139Iobit advanced system care exposure of resource to wrong sphere vulnerabilityIn IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCSe…EPSS 0.37%5.5CVE-2024-1195Iobit itop vpn improper resource shutdown vulnerabilityA vulnerability classified as critical was found in iTop VPN up to 4.0.0.1. Affected by this vulnerability is an unknown functionality in the library…EPSS 0.26%5.4CVE-2022-24141Iobit itop vpn vulnerabilityThe iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe wi…EPSS 0.58%7.8CVE-2026-3502TrueConf Client update download lacks integrity check, enabling code executionTrueConf Client downloads application update code and applies it without verifying its integrity (CWE-494). An attacker who can influence the update …KEVEPSS 0.33%analysed7.7CVE-2025-15556Notepad++ WinGUp updater lacks update integrity verificationNotepad++ versions prior to 8.8.9 use the WinGUp updater, which downloads update metadata and installers without cryptographic verification. An attac…KEVEPSS 1.7%analysed8.8CVE-2022-40799D-Link DNR-322L backup config command injectionThe 'Backup Config' function in D-Link DNR-322L firmware 2.60B15 and earlier fails to verify the integrity of downloaded code, allowing an authentica…KEVEPSS 34%analysed

Source: NIST National Vulnerability Database (record CVE-2022-24140), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.