← Vulnerability feed

Vulnerability record · CVE-2023-1646 · published 26 March 2023

CVE-2023-1646: Iobit malware fighter stack-based buffer overflow vulnerability

Iobit · Malware Fighter

A vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x8018E004 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. VDB-224026 is the identifier assigned to this vulnerability.

7.8 CVSS 3.1 High EPSS 0.37% · top 71.3% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 4.3
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x8018E004 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. VDB-224026 is the identifier assigned to this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1646 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2016-20059Iobit malware fighter unquoted search path vulnerabilityIObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers …EPSS 0.18%7.8CVE-2020-23864Iobit malware fighter vulnerabilityAn issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the Windo…EPSS 0.51%7.8CVE-2018-19084Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E05C with a size larger …EPSS 0.60%7.8CVE-2018-19085Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E048 with a size larger …EPSS 0.60%7.8CVE-2018-19086Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E040 with a size larger …EPSS 0.60%7.8CVE-2018-19087Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E044 with a size larger …EPSS 0.60%7.8CVE-2018-18714Iobit malware fighter out-of-bounds write vulnerabilityRegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This c…EPSS 0.87%7.8CVE-2018-18026Iobit malware fighter out-of-bounds write vulnerabilityIMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use …EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2023-1646), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.