CVE-2019-6494: Iobit Malware Fighter

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

IMFForceDelete.sys in IObit Malware Fighter 6.2 allows a low privileged user to send IOCTL 0x8016E000 along with a user defined string to a file; that file will be promptly deleted regardless of access controls.

Affected products

  • Iobit Malware Fighter: version 6.2 only

Published 2019-04-30. Last modified 2026-06-17.