IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP requests in their update procedure in order to download a config file. After downloading the config file, the products will parse the HTTP location of the update from the file and will try to install the update automatically with ADMIN privileges. An attacker Intercepting this communication can supply the product a fake config file with malicious locations for the updates thus gaining a remote code execution on an endpoint.
Conclusion & alert: CVE-2022-24140 is rated Moderate Risk (42.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.77%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.21% | 0.77% | -1.44% |
| 2 | 2026-01-31 | 0.89% | 2.21% | +1.33% |
| 3 | 2025-07-07 | — | 0.89% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.6 | 3.1 | MEDIUM |
|
0.7 | 5.9 | [email protected] |
| 6.0 | 2.0 | MEDIUM |
|
6.8 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| iobit | advanced_system_care | 15 | cpe:2.3:a:iobit:advanced_system_care:15:*:*:*:free:*:*:* |
| iobit | advanced_system_care | 15 | cpe:2.3:a:iobit:advanced_system_care:15:*:*:*:pro:*:*:* |
| iobit | driver_booster | 9 | cpe:2.3:a:iobit:driver_booster:9:*:*:*:*:*:*:* |
| iobit | itop_screen_recorder | 2.1 | cpe:2.3:a:iobit:itop_screen_recorder:2.1:*:*:*:*:*:*:* |
| iobit | itop_screenshot | — | cpe:2.3:a:iobit:itop_screenshot:-:*:*:*:*:*:*:* |
| iobit | itop_vpn | 3.2 | cpe:2.3:a:iobit:itop_vpn:3.2:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://advanced.com | Not Applicable |
| http://iobit.com | Vendor Advisory |
| https://github.com/tomerpeled92/CVE/ | Third Party Advisory |