Falhas do tipo CWE-782

40 resultados

IOCTL Exposto com Controle de Acesso Insuficiente

Uma operação IOCTL (comando de controle de dispositivo) fica acessível a usuários sem privilégios suficientes, permitindo que qualquer processo execute ações administrativas ou acesse dados sensíveis do kernel/hardware. O erro ocorre quando o driver não valida adequadamente quem está tentando chamar a operação, ou valida de forma incompleta.

Exemplo

Um driver de GPU expõe um IOCTL para resetar memória de vídeo, mas não verifica se o processo que o chamou está em grupo de usuários autorizados. Um app malicioso consegue invocar o IOCTL e interferir no funcionamento de outro processo gráfico, ou vazar dados de memória de vídeo.

Como mitigar

Validar e enforçar permissões antes de processar qualquer IOCTL: verificar UID/GID, capabilities do processo, ou usar mecanismos como SELinux/AppArmor. Nunca confiar no usuário que faz a chamada; implementar controle de acesso explícito e granular para cada operação sensível.

CVE-2021-21786HIGHA privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially cEPSS 0.3%CVE-2021-25695The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attackEPSS 0.3%CVE-2024-33219HIGHAn issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges andEPSS 0.3%CVE-2024-33218HIGHAn issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privEPSS 0.2%CVE-2024-33222HIGHAn issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execuEPSS 0.2%CVE-2026-38764HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.2%CVE-2024-33221HIGHAn issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges andEPSS 0.2%CVE-2023-44976LOWHangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeEPSS 0.2%CVE-2026-38766HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 functionEPSS 0.2%CVE-2026-38765HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.2%CVE-2026-57851HIGHMSI KernCoreLib64.sys Privilege Escalation via IOCTL HandlersEPSS 0.2%CVE-2025-15641MEDIUMNetskope Client Exposed IOCTL with Insufficient Access ControlsEPSS 0.2%CVE-2026-8501HIGHCVE-2026-8501EPSS 0.2%CVE-2025-47761HIGHAn Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, EPSS 0.2%CVE-2026-8797HIGHAn access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitEPSS 0.1%CVE-2026-56129MEDIUMGeneric IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access contrEPSS 0.1%CVE-2026-9492HIGHGIGABYTE|Gigabyte Control Center - Improper Access ControlEPSS 0.1%CVE-2025-27535MEDIUMExposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 wiEPSS 0.1%CVE-2026-6737LOWAn Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms anEPSS 0.1%CVE-2019-25764HIGH**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass theEPSS 0.1%