VYPR

CWE-782

Exposed IOCTL with Insufficient Access Control

VariantDraft

Description

The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (40)

page 2 of 2
  • CVE-2025-26125HigMar 17, 2025
    risk 0.47cvss 7.3epss 0.01

    An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.

  • CVE-2026-4483HigApr 8, 2026
    risk 0.46cvss epss 0.00

    An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system…

  • CVE-2025-8061HigSep 11, 2025
    risk 0.46cvss 7.0epss 0.00

    A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2…

  • CVE-2025-15641MedJun 17, 2026
    risk 0.44cvss epss 0.00

    Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the…

  • CVE-2024-0141MedMar 5, 2025
    risk 0.44cvss 6.8epss 0.01

    NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write to an unsupported registry causing a bad state. A successful exploit of this vulnerability may lead to denial of service.

  • CVE-2021-21792MedAug 5, 2021
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in…

  • CVE-2021-21791MedAug 5, 2021
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in…

  • CVE-2021-21790MedAug 5, 2021
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in…

  • CVE-2021-21785MedAug 5, 2021
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially crafted I/O request packet (IRP) can lead to a disclosure of sensitive information. An attacker can send a malicious IRP to trigger this…

  • CVE-2025-27535MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a high complexity…

  • CVE-2023-44976LowAug 1, 2025
    risk 0.21cvss 3.2epss 0.00

    Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeviceIoControl with control code 0x22E010, as exploited in the wild in October 2023.

  • CVE-2026-6737LowMay 8, 2026
    risk 0.13cvss epss 0.00

    An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or render the touchpad unusable via crafted IOCTL requests.Refer to the ' Security Update for…

  • CVE-2026-38764HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

  • CVE-2026-38766HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

  • CVE-2026-38765HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

  • CVE-2019-25764HigJul 17, 2026
    risk 0.00cvss epss 0.00

    **UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update…

  • CVE-2026-9492HigJul 13, 2026
    risk 0.00cvss 7.8epss 0.00

    The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the…

  • CVE-2026-57851HigJul 7, 2026
    risk 0.00cvss 7.8epss 0.00

    MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without…

  • CVE-2026-8797HigJun 26, 2026
    risk 0.00cvss epss 0.00

    An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.

  • CVE-2026-56129MedJun 25, 2026
    risk 0.00cvss 5.5epss 0.00

    Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.