VYPR

CWE-782

Exposed IOCTL with Insufficient Access Control

VariantDraft

Description

The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (14)

  • CVE-2024-39251CriJul 1, 2024
    risk 0.65cvss 10.0epss 0.01

    An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending crafted IOCTL requests.

  • CVE-2024-30804CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

  • CVE-2025-7771HigAug 6, 2025
    risk 0.60cvss epss 0.09

    ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel…

  • CVE-2024-33222HigMay 22, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

  • CVE-2026-36355HigMay 5, 2026
    risk 0.53cvss 7.7epss 0.01

    The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5) and read_mem (ioctl 0x89F6) debug handlers, which are compiled into production builds via the…

  • CVE-2026-8501HigJun 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected…

  • CVE-2024-33221HigMay 22, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

  • CVE-2024-33218HigMay 22, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

  • CVE-2025-26125HigMar 17, 2025
    risk 0.47cvss 7.3epss 0.00

    An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

  • CVE-2026-4483HigApr 8, 2026
    risk 0.46cvss epss 0.00

    An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system…

  • CVE-2025-8061HigSep 11, 2025
    risk 0.46cvss 7.0epss 0.00

    A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2…

  • CVE-2024-0141MedMar 5, 2025
    risk 0.44cvss 6.8epss 0.01

    NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write to an unsupported registry causing a bad state. A successful exploit of this vulnerability may lead to denial of service.

  • CVE-2023-44976LowAug 1, 2025
    risk 0.21cvss 3.2epss 0.00

    Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as exploited in the wild in October 2023.

  • CVE-2026-6737LowMay 8, 2026
    risk 0.13cvss epss 0.00

    An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or render the touchpad unusable via crafted IOCTL requests.Refer to the ' Security Update for…