CVE-2026-90485 Details
Description
A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been published and may be used. Identical IURegistryFilter.sys ships across multiple IObit families. The vendor was contacted early about this disclosure but did not respond in any way.
A null pointer dereference vulnerability has been identified in IOBit Uninstaller version 15.5.0.11. The issue arises in the IOCTL Dispatch Handler, specifically within the function sub_11838 of the file IURegistryFilter.sys. This vulnerability requires local access to exploit.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 12, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/887954 | CISA-ADP | Issue TrackingPermission Required |
| https://vuldb.com/cve/CVE-2026-90485 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/887954 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403064 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403064/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| IOBit Uninstaller | 15.5.0.11 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 12, 2026 | New CVE Received | [email protected] |
Volerion