LiveActive security incident?Get immediate response
CVE Record

CVE-2021-21785: An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCar...

An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to a disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.

MediumCVSS 6.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-21785 can let a low-privileged local attacker obtain sensitive information from IOBit Advanced SystemCare Ultimate 14.2.0.220. This is not a remote internet-facing issue based on the supplied CVSS vector, but it can matter on shared endpoints or systems where local compromise is already possible.

Executive priority

Treat this as a targeted endpoint hygiene issue, not an emergency internet-scale event. Prioritize discovery and remediation where the product runs on sensitive or multi-user systems, especially if local privilege separation is important.

Technical view

The issue is an information disclosure flaw in IOCTL 0x9c40a148 handling. A specially crafted IRP can trigger sensitive information disclosure. The supplied CVSS vector indicates local access, low attack complexity, low privileges required, no user interaction, changed scope, and high confidentiality impact.

Likely exposure

Exposure appears limited to systems running IOBit Advanced SystemCare Ultimate 14.2.0.220. The bundle does not identify affected CPEs, other versions, specific driver names, or whether server installations are plausible.

Exploitation context

The supplied data does not show CISA KEV listing or active exploitation. Exploitation requires local access and low privileges, so the main risk is post-compromise information disclosure on affected endpoints.

Researcher notes

Evidence is strongest for the affected version, IOCTL class, impact type, and local-privileged exploitation requirements. The provided sources do not establish exploit-in-the-wild activity, public weaponization, a fixed version, or broader version impact.

Mitigation direction

  • Inventory endpoints for IOBit Advanced SystemCare Ultimate 14.2.0.220.
  • Check Talos and vendor guidance for confirmed patched versions or workarounds.
  • Upgrade, remove, or disable the affected product where business need is low.
  • Limit local user privileges on systems where the product remains installed.
  • Prioritize shared, kiosk, lab, and high-sensitivity endpoints.

Validation and detection

  • Confirm whether version 14.2.0.220 is installed on managed endpoints.
  • Verify the affected product components are enabled before marking a host exposed.
  • Review EDR or endpoint telemetry for unusual local access to the product driver or service.
  • Document any vendor-confirmed fixed version before closing remediation tickets.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-782: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-21785 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.5 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.5CVSS 3.0MediumCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N24Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

6.5Medium
CVSS 3.0 vector shape for CVE-2021-21785Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aIOBitIOBit Advanced SystemCare Ultimate 14.2.0.220Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-782 · source CWE mapping

Exposed IOCTL with Insufficient Access Control

Exposed IOCTL with Insufficient Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.