Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.
References
Configurations
No configuration.
History
21 Nov 2024, 09:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://jvn.jp/en/vu/JVNVU90671953/ - | |
| References | () https://sangomakb.atlassian.net/wiki/spaces/DVC/pages/45351279/Natural+Access+Software+Download - |
07 Nov 2024, 17:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-522 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
25 Mar 2024, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-03-25 07:15
Updated : 2024-11-21 09:07
NVD link : CVE-2024-29216
Mitre link : CVE-2024-29216
CVE.ORG link : CVE-2024-29216
JSON object : View
Products Affected
No product.
CWE
CWE-522
Insufficiently Protected Credentials
