Vulnerability record · CVE-2022-24562 · published 16 June 2022
CVE-2022-24562: IOBit IOTransfer Airserv missing authentication allows remote file access and RCE
Iobit · Iotransfer
IOBit IOTransfer 4.3.1.1561 exposes an Airserv service that accepts GET and POST requests without authentication. An unauthenticated attacker can use it to read and write the entire file system with admin privileges, leading to data theft and remote code execution.
Description
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, full confidentiality, integrity and availability impact, and public exploit references make this a critical exposure for any host running the affected IOTransfer build.
What it is
IOBit IOTransfer 4.3.1.1561 exposes an Airserv service that accepts GET and POST requests without authentication. An unauthenticated attacker can use it to read and write the entire file system with admin privileges, leading to data theft and remote code execution.
Impact
An attacker gains arbitrary read/write access to the victim endpoint's file system at admin privilege level, enabling data theft and remote code execution on the host.
Attack surface
Reachable over the network via the Airserv HTTP interface using GET and POST requests; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is high (0.54483, ~99th percentile) and public exploit references exist, including a Packet Storm exploit writeup and a Medium analysis, indicating public exploitation detail is available.
What to do
- Upgrade IOTransfer to a version later than 4.3.1.1561 if the vendor provides one; verify with IOBit before relying on any specific fixed build.
- If the Airserv component is not required, disable or block it and stop the IOTransfer service on endpoints.
- Restrict network access to the Airserv port with host firewall rules so only trusted management hosts can reach it.
- Run IOTransfer with the least privilege possible rather than admin rights to limit the impact of file-system access.
- Monitor for unexpected inbound connections to IOTransfer/Airserv ports and treat any exposure as a compromise indicator.
Detection
- Monitor network traffic for GET/POST requests to the IOTransfer Airserv service from untrusted hosts.
- Alert on IOTransfer processes spawning child processes such as cmd.exe or PowerShell, which may indicate RCE.
- Audit file-system writes and reads by IOTransfer processes outside expected transfer directories.
- Check endpoint logs for IOTransfer listening on network interfaces where it should not be exposed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-24562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24562), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.