CWE-782 · 43 записей
Exposed IOCTL with Insufficient Access Control
CVE этого класса
43 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
85Срочно | CVE-2021-21551Готовый эксплойт | Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servidell · dbutil · CWE-782 | Высокая7,8 | KEV | 79,2 % | 4 мая 2021 г. |
40В плане | CVE-2024-39251Эксплойта нет | An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitiveCWE-782 | Критическая10,0 | — | 0,7 % | 1 июл. 2024 г. |
39Наблюдать | CVE-2024-32370Proof of concept | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a craftehsclabs · mailinspector · CWE-782 | Критическая9,8 | — | 1,0 % | 7 мая 2024 г. |
39Наблюдать | CVE-2024-30804Proof of concept | An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via craftCWE-782 | Критическая9,8 | — | 0,8 % | 26 апр. 2024 г. |
39Наблюдать | CVE-2024-4196Эксплойта нет | Avaya IP Office Web Control RCE Vulnerabilityavaya · ip office · CWE-782 | Критическая9,8 | — | 0,6 % | 25 июн. 2024 г. |
36Наблюдать | CVE-2025-7771Proof of concept | Code Execution / Escalation of Privileges in ThrottleStoptechpowerup · throttlestop · CWE-782 | Высокая8,7 | — | 7,2 % | 6 авг. 2025 г. |
35Наблюдать | CVE-2024-33220Эксплойта нет | An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and executeasus · ai suite · CWE-782 | Высокая8,8 | — | 0,7 % | 22 мая 2024 г. |
35Наблюдать | CVE-2021-21787Эксплойта нет | A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write reqiobit · advanced systemcare ultimate · CWE-782 | Высокая8,8 | — | 0,3 % | 7 июл. 2021 г. |
35Наблюдать | CVE-2021-21788Эксплойта нет | A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write reqiobit · advanced systemcare ultimate · CWE-782 | Высокая8,8 | — | 0,3 % | 7 июл. 2021 г. |
35Наблюдать | CVE-2021-21789Эксплойта нет | A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write reqiobit · advanced systemcare ultimate · CWE-782 | Высокая8,8 | — | 0,3 % | 7 июл. 2021 г. |
34Наблюдать | CVE-2026-84408Эксплойта нет | QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC whequalitysoft corporation · qnd premium · CWE-782 | Высокая8,7 | — | 0,6 % | 16 сент. 2026 г. |
34Наблюдать | CVE-2026-80116Эксплойта нет | PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTLpassmark software · performancetest · CWE-782 | Высокая8,5 | — | 0,2 % | 4 сент. 2026 г. |
34Наблюдать | CVE-2026-57851Proof of concept | MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlersmicro-star international (msi) · kerncorelib64.sys · CWE-782 | Высокая8,5 | — | 0,2 % | 7 июл. 2026 г. |
34Наблюдать | CVE-2026-9492Эксплойта нет | GIGABYTE|Gigabyte Control Center - Improper Access Controlgigabyte · mbstorage · CWE-782 | Высокая8,5 | — | 0,2 % | 13 июл. 2026 г. |
34Наблюдать | CVE-2026-8797Эксплойта нет | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows.nec corporation · expressupdate agent for windows · CWE-782 | Высокая8,5 | — | 0,1 % | 26 июн. 2026 г. |
33Наблюдать | CVE-2024-33222Эксплойта нет | An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execuCWE-782 | Высокая8,4 | — | 0,2 % | 22 мая 2024 г. |
31Наблюдать | CVE-2021-21786Эксплойта нет | A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220.iobit · advanced systemcare ultimate · CWE-782 | Высокая7,8 | — | 0,3 % | 7 июл. 2021 г. |
31Наблюдать | CVE-2021-25695Эксплойта нет | The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attackteradici · pcoip · CWE-782 | Высокая7,8 | — | 0,3 % | 21 июл. 2021 г. |
31Наблюдать | CVE-2024-33219Эксплойта нет | An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges andasus · sabertooth x99 firmware · CWE-782 | Высокая7,8 | — | 0,3 % | 22 мая 2024 г. |
31Наблюдать | CVE-2024-33218Эксплойта нет | An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privCWE-782 | Высокая7,8 | — | 0,2 % | 22 мая 2024 г. |
31Наблюдать | CVE-2026-8501Эксплойта нет | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the symantec · pc tools internet security · CWE-782 | Высокая7,8 | — | 0,2 % | 1 июн. 2026 г. |
31Наблюдать | CVE-2024-33221Эксплойта нет | An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges andCWE-782 | Высокая7,8 | — | 0,2 % | 22 мая 2024 г. |
31Наблюдать | CVE-2025-47761Эксплойта нет | An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, fortinet · forticlient · CWE-782 | Высокая7,8 | — | 0,2 % | 18 нояб. 2025 г. |
29Наблюдать | CVE-2025-26125Proof of concept | An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate priCWE-782 | Высокая7,3 | — | 0,5 % | 17 мар. 2025 г. |
29Наблюдать | CVE-2025-8061Proof of concept | A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenolenovo · dispatcher 3.0 driver · CWE-782 | Высокая7,3 | — | 0,4 % | 11 сент. 2025 г. |
- CVE-2021-2155185Срочно
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servi
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 79 %dell · dbutil4 мая 2021 г.
- CVE-2024-3925140В плане
An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %1 июл. 2024 г.
- CVE-2024-3237039Наблюдать
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafte
КритическаяCVSS 9,8Proof of conceptEPSS 1 %hsclabs · mailinspector7 мая 2024 г.
- CVE-2024-3080439Наблюдать
An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via craft
КритическаяCVSS 9,8Proof of conceptEPSS 1 %26 апр. 2024 г.
- CVE-2024-419639Наблюдать
Avaya IP Office Web Control RCE Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %avaya · ip office25 июн. 2024 г.
- CVE-2025-777136Наблюдать
Code Execution / Escalation of Privileges in ThrottleStop
ВысокаяCVSS 8,7Proof of conceptEPSS 7 %techpowerup · throttlestop6 авг. 2025 г.
- CVE-2024-3322035Наблюдать
An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %asus · ai suite22 мая 2024 г.
- CVE-2021-2178735Наблюдать
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write req
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %iobit · advanced systemcare ultimate7 июл. 2021 г.
- CVE-2021-2178835Наблюдать
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write req
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %iobit · advanced systemcare ultimate7 июл. 2021 г.
- CVE-2021-2178935Наблюдать
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write req
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %iobit · advanced systemcare ultimate7 июл. 2021 г.
- CVE-2026-8440834Наблюдать
QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC whe
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %qualitysoft corporation · qnd premium16 сент. 2026 г.
- CVE-2026-8011634Наблюдать
PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %passmark software · performancetest4 сент. 2026 г.
- CVE-2026-5785134Наблюдать
MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
ВысокаяCVSS 8,5Proof of conceptEPSS 0 %micro-star international (msi) · kerncorelib64.sys7 июл. 2026 г.
- CVE-2026-949234Наблюдать
GIGABYTE|Gigabyte Control Center - Improper Access Control
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %gigabyte · mbstorage13 июл. 2026 г.
- CVE-2026-879734Наблюдать
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows.
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %nec corporation · expressupdate agent for windows26 июн. 2026 г.
- CVE-2024-3322233Наблюдать
An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execu
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %22 мая 2024 г.
- CVE-2021-2178631Наблюдать
A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %iobit · advanced systemcare ultimate7 июл. 2021 г.
- CVE-2021-2569531Наблюдать
The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attack
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %teradici · pcoip21 июл. 2021 г.
- CVE-2024-3321931Наблюдать
An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %asus · sabertooth x99 firmware22 мая 2024 г.
- CVE-2024-3321831Наблюдать
An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate priv
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %22 мая 2024 г.
- CVE-2026-850131Наблюдать
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %symantec · pc tools internet security1 июн. 2026 г.
- CVE-2024-3322131Наблюдать
An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %22 мая 2024 г.
- CVE-2025-4776131Наблюдать
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3,
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %fortinet · forticlient18 нояб. 2025 г.
- CVE-2025-2612529Наблюдать
An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate pri
ВысокаяCVSS 7,3Proof of conceptEPSS 1 %17 мар. 2025 г.
- CVE-2025-806129Наблюдать
A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Leno
ВысокаяCVSS 7,3Proof of conceptEPSS 0 %lenovo · dispatcher 3.0 driver11 сент. 2025 г.