CVE-2023-35841

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
Configurations

No configuration.

History

28 Jul 2025, 21:15

Type Values Removed Values Added
References
  • () https://phoenixtech.com/phoenix-security-notifications/cve-2023-35841/ -
Summary (en) Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0. (en) Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

Information

Published : 2024-05-14 16:15

Updated : 2025-07-28 21:15


NVD link : CVE-2023-35841

Mitre link : CVE-2023-35841

CVE.ORG link : CVE-2023-35841


JSON object : View

Products Affected

No product.

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-782

Exposed IOCTL with Insufficient Access Control