SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90485

MEDIUM · CVSS 5.5 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

A null pointer dereference vulnerability exists in the IOCTL Dispatch Handler of IURegistryFilter.sys in IOBit Uninstaller 15.5.0.11, allowing local attackers to potentially exploit the flaw. Organizations using this software should prioritize remediation efforts, as the exploit has been publicly disclosed and could lead to system instability or unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90485
Severity
MEDIUM
CVSS
5.5
EPSS
N/A

Original NVD Description

A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been published and may be used. Identical IURegistryFilter.sys ships across multiple IObit families. The vendor was contacted early about this disclosure but did not respond in any way.