An issue in IObit Unlocker v1.3.0.11 allows an attacker to trigger a Denial of Service condition by sending a crafted request to the Unlocker component, causing the application to crash or become unresponsive.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository implements a local Windows exploit/abuse tool for CVE-2025-66676 affecting IObit Unlocker <= 1.3.0.11. The core is a C++ console application (IObitUnlockerKiller.cpp) that (1) creates and starts a kernel-driver service named "IObitUnlocker" pointing to C:\Windows\System32\Drivers\IObitUnlocker.sys, (2) opens the device \\.\IObitUnlockerDevice, and (3) repeatedly reads newline-separated target image paths from p.txt and sends IOCTL 0x222124 with a packed buffer containing the ImagePath and Flag=0x7. Successful calls report that the process at the given image path will be terminated. A key component is bypassing the driver’s user-mode validation: the README explains the driver checks two checksums (XOR-of-bytes and an alternating +/- sum) against fixed values. The provided Python script patch_exe.py appends padding bytes (including a brute-forced final 3-byte solution) to the compiled exploit executable so its checksums match the hardcoded targets (XOR=43, alt-sum=11044471). check_xor_alt.py is a helper to compute these checksums (over the first 3MB in that script). Structure: a Visual Studio solution/project for building the exploit (sln/vcxproj + resource.h) and two Python utilities under Release/ for checksum calculation and binary padding. No network C2 or remote endpoints are present; the attack vector is purely local and requires admin rights to load the driver. The overall purpose is arbitrary kernel-assisted process termination (commonly positioned as an EDR-killer technique) by abusing IObit Unlocker’s driver interface and bypassing its simplistic checksum gate.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.