CWE-782
Exposed IOCTL with Insufficient Access Control
Description
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (48)
page 3 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-38764 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | ||
| CVE-2026-38766 | Hig | 0.00 | 7.8 | 0.00 | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function | ||
| CVE-2026-38765 | Hig | 0.00 | 7.8 | 0.00 | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | ||
| CVE-2019-25764 | Hig | 0.00 | — | 0.00 | Jul 17, 2026 | **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update… | ||
| CVE-2026-9492 | Hig | 0.00 | 7.8 | 0.00 | Jul 13, 2026 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the… | ||
| CVE-2026-57851 | Hig | 0.00 | 7.8 | 0.00 | Jul 7, 2026 | MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without… | ||
| CVE-2026-8797 | Hig | 0.00 | — | 0.00 | Jun 26, 2026 | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges. | ||
| CVE-2026-56129 | Med | 0.00 | 5.5 | 0.00 | Jun 25, 2026 | Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory. |
- risk 0.00cvss 7.8epss 0.00
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
- risk 0.00cvss 7.8epss 0.00
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function
- risk 0.00cvss 7.8epss 0.00
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
- risk 0.00cvss —epss 0.00
**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update…
- risk 0.00cvss 7.8epss 0.00
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the…
- risk 0.00cvss 7.8epss 0.00
MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without…
- risk 0.00cvss —epss 0.00
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.
- risk 0.00cvss 5.5epss 0.00
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.