CVE-2026-4483

An exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system memory. A local attacker with high privileges could abuse these interfaces to perform unauthorized operations. Successful exploitation may result in privilege escalation on Windows 7 systems or cause a system crash (BSoD) on Windows 10 and 11 systems, leading to a denial-of-service condition. The vulnerability could slightly affect the confidentiality and integrity of the device, but availability might be heavily impacted. No impact to the subsequent system has been identified.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Un IOCTL expuesto con una vulnerabilidad de control de acceso insuficiente ha sido identificado en la utilidad, MxGeneralIo, para los ordenadores industriales x86 de Moxa. La utilidad afectada, MxGeneralIo, expone métodos IOCTL que permiten acceso directo de lectura y escritura a MSR y a la memoria del sistema. Un atacante local con privilegios elevados podría abusar de estas interfaces para realizar operaciones no autorizadas. La explotación exitosa puede resultar en escalada de privilegios en sistemas Windows 7 o causar un fallo del sistema (BSoD) en sistemas Windows 10 y 11, lo que lleva a una condición de denegación de servicio. La vulnerabilidad podría afectar ligeramente la confidencialidad e integridad del dispositivo, pero la disponibilidad podría verse gravemente impactada. Ningún impacto en el sistema subsiguiente ha sido identificado.

08 Apr 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 08:16

Updated : 2026-07-24 20:10


NVD link : CVE-2026-4483

Mitre link : CVE-2026-4483

CVE.ORG link : CVE-2026-4483


JSON object : View

Products Affected

No product.

CWE
CWE-782

Exposed IOCTL with Insufficient Access Control