Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-03-25 07:15
Updated : 2024-11-21 09:07
NVD link : CVE-2024-29216
Mitre link : CVE-2024-29216
CVE.ORG link : CVE-2024-29216
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials