CVE-2022-24140 - CVE House
Back to Database
Status published Medium CVE-2022-24140

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop...

Vulnerability Description

IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24140

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

advanced system care, driver booster, itop screen recorder, itop screenshot, itop vpn
Vulnerable Versions:
15, 9, 2.1, 3.2

Timeline

Official Publish: July 6th, 2022
Last Modified: July 9th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.