CVE-2025-0222
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jan 5, 2025
Updated: Jan 23, 2025
CWE ID 404
CWE ID 476
Summary
CVE-2025-0222: A locally exploitable null pointer dereference vulnerability was identified in IObit Protected Folder up to version 13.6.0.5. This issue resides in the IUProcessFilter.sys library's IOCTL Handler function with addresses 0x8001E000 and 0x8001E004. Exploitation of this vulnerability results in a null pointer dereference, potentially leading to system instability or arbitrary code execution. The exploit for this issue has been made public, increasing the risk to affected systems, despite early attempts to alert the vendor.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.