VYPR

CWE-782

Exposed IOCTL with Insufficient Access Control

VariantDraft

Description

The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (48)

page 3 of 3
  • CVE-2026-38764HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

  • CVE-2026-38766HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

  • CVE-2026-38765HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

  • CVE-2019-25764HigJul 17, 2026
    risk 0.00cvss —epss 0.00

    **UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update…

  • CVE-2026-9492HigJul 13, 2026
    risk 0.00cvss 7.8epss 0.00

    The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the…

  • CVE-2026-57851HigJul 7, 2026
    risk 0.00cvss 7.8epss 0.00

    MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without…

  • CVE-2026-8797HigJun 26, 2026
    risk 0.00cvss —epss 0.00

    An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.

  • CVE-2026-56129MedJun 25, 2026
    risk 0.00cvss 5.5epss 0.00

    Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.