CWE-782 · 43 kayıt
Exposed IOCTL with Insufficient Access Control
Bu sınıftaki CVE’ler
43 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
85Hemen | CVE-2021-21551Silahlaştırılmış | Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servidell · dbutil · CWE-782 | Yüksek7,8 | KEV | %79,2 | 4 May 2021 |
40Planlayın | CVE-2024-39251İstismar yok | An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitiveCWE-782 | Kritik10,0 | — | %0,7 | 1 Tem 2024 |
39İzleyin | CVE-2024-32370Kavram kanıtı | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a craftehsclabs · mailinspector · CWE-782 | Kritik9,8 | — | %1,0 | 7 May 2024 |
39İzleyin | CVE-2024-30804Kavram kanıtı | An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via craftCWE-782 | Kritik9,8 | — | %0,8 | 26 Nis 2024 |
39İzleyin | CVE-2024-4196İstismar yok | Avaya IP Office Web Control RCE Vulnerabilityavaya · ip office · CWE-782 | Kritik9,8 | — | %0,6 | 25 Haz 2024 |
36İzleyin | CVE-2025-7771Kavram kanıtı | Code Execution / Escalation of Privileges in ThrottleStoptechpowerup · throttlestop · CWE-782 | Yüksek8,7 | — | %7,2 | 6 Ağu 2025 |
35İzleyin | CVE-2024-33220İstismar yok | An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and executeasus · ai suite · CWE-782 | Yüksek8,8 | — | %0,7 | 22 May 2024 |
35İzleyin | CVE-2021-21787İstismar yok | A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write reqiobit · advanced systemcare ultimate · CWE-782 | Yüksek8,8 | — | %0,3 | 7 Tem 2021 |
35İzleyin | CVE-2021-21788İstismar yok | A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write reqiobit · advanced systemcare ultimate · CWE-782 | Yüksek8,8 | — | %0,3 | 7 Tem 2021 |
35İzleyin | CVE-2021-21789İstismar yok | A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write reqiobit · advanced systemcare ultimate · CWE-782 | Yüksek8,8 | — | %0,3 | 7 Tem 2021 |
34İzleyin | CVE-2026-84408İstismar yok | QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC whequalitysoft corporation · qnd premium · CWE-782 | Yüksek8,7 | — | %0,6 | 16 Eyl 2026 |
34İzleyin | CVE-2026-80116İstismar yok | PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTLpassmark software · performancetest · CWE-782 | Yüksek8,5 | — | %0,2 | 4 Eyl 2026 |
34İzleyin | CVE-2026-57851Kavram kanıtı | MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlersmicro-star international (msi) · kerncorelib64.sys · CWE-782 | Yüksek8,5 | — | %0,2 | 7 Tem 2026 |
34İzleyin | CVE-2026-9492İstismar yok | GIGABYTE|Gigabyte Control Center - Improper Access Controlgigabyte · mbstorage · CWE-782 | Yüksek8,5 | — | %0,2 | 13 Tem 2026 |
34İzleyin | CVE-2026-8797İstismar yok | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows.nec corporation · expressupdate agent for windows · CWE-782 | Yüksek8,5 | — | %0,1 | 26 Haz 2026 |
33İzleyin | CVE-2024-33222İstismar yok | An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execuCWE-782 | Yüksek8,4 | — | %0,2 | 22 May 2024 |
31İzleyin | CVE-2021-21786İstismar yok | A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220.iobit · advanced systemcare ultimate · CWE-782 | Yüksek7,8 | — | %0,3 | 7 Tem 2021 |
31İzleyin | CVE-2021-25695İstismar yok | The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attackteradici · pcoip · CWE-782 | Yüksek7,8 | — | %0,3 | 21 Tem 2021 |
31İzleyin | CVE-2024-33219İstismar yok | An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges andasus · sabertooth x99 firmware · CWE-782 | Yüksek7,8 | — | %0,3 | 22 May 2024 |
31İzleyin | CVE-2024-33218İstismar yok | An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privCWE-782 | Yüksek7,8 | — | %0,2 | 22 May 2024 |
31İzleyin | CVE-2026-8501İstismar yok | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the symantec · pc tools internet security · CWE-782 | Yüksek7,8 | — | %0,2 | 1 Haz 2026 |
31İzleyin | CVE-2024-33221İstismar yok | An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges andCWE-782 | Yüksek7,8 | — | %0,2 | 22 May 2024 |
31İzleyin | CVE-2025-47761İstismar yok | An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, fortinet · forticlient · CWE-782 | Yüksek7,8 | — | %0,2 | 18 Kas 2025 |
29İzleyin | CVE-2025-26125Kavram kanıtı | An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate priCWE-782 | Yüksek7,3 | — | %0,5 | 17 Mar 2025 |
29İzleyin | CVE-2025-8061Kavram kanıtı | A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenolenovo · dispatcher 3.0 driver · CWE-782 | Yüksek7,3 | — | %0,4 | 11 Eyl 2025 |
- CVE-2021-2155185Hemen
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servi
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %79dell · dbutil4 May 2021
- CVE-2024-3925140Planlayın
An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive
KritikCVSS 10,0İstismar yokEPSS %11 Tem 2024
- CVE-2024-3237039İzleyin
An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafte
KritikCVSS 9,8Kavram kanıtıEPSS %1hsclabs · mailinspector7 May 2024
- CVE-2024-3080439İzleyin
An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via craft
KritikCVSS 9,8Kavram kanıtıEPSS %126 Nis 2024
- CVE-2024-419639İzleyin
Avaya IP Office Web Control RCE Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1avaya · ip office25 Haz 2024
- CVE-2025-777136İzleyin
Code Execution / Escalation of Privileges in ThrottleStop
YüksekCVSS 8,7Kavram kanıtıEPSS %7techpowerup · throttlestop6 Ağu 2025
- CVE-2024-3322035İzleyin
An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute
YüksekCVSS 8,8İstismar yokEPSS %1asus · ai suite22 May 2024
- CVE-2021-2178735İzleyin
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write req
YüksekCVSS 8,8İstismar yokEPSS %0iobit · advanced systemcare ultimate7 Tem 2021
- CVE-2021-2178835İzleyin
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write req
YüksekCVSS 8,8İstismar yokEPSS %0iobit · advanced systemcare ultimate7 Tem 2021
- CVE-2021-2178935İzleyin
A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write req
YüksekCVSS 8,8İstismar yokEPSS %0iobit · advanced systemcare ultimate7 Tem 2021
- CVE-2026-8440834İzleyin
QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC whe
YüksekCVSS 8,7İstismar yokEPSS %1qualitysoft corporation · qnd premium16 Eyl 2026
- CVE-2026-8011634İzleyin
PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL
YüksekCVSS 8,5İstismar yokEPSS %0passmark software · performancetest4 Eyl 2026
- CVE-2026-5785134İzleyin
MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
YüksekCVSS 8,5Kavram kanıtıEPSS %0micro-star international (msi) · kerncorelib64.sys7 Tem 2026
- CVE-2026-949234İzleyin
GIGABYTE|Gigabyte Control Center - Improper Access Control
YüksekCVSS 8,5İstismar yokEPSS %0gigabyte · mbstorage13 Tem 2026
- CVE-2026-879734İzleyin
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows.
YüksekCVSS 8,5İstismar yokEPSS %0nec corporation · expressupdate agent for windows26 Haz 2026
- CVE-2024-3322233İzleyin
An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execu
YüksekCVSS 8,4İstismar yokEPSS %022 May 2024
- CVE-2021-2178631İzleyin
A privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220.
YüksekCVSS 7,8İstismar yokEPSS %0iobit · advanced systemcare ultimate7 Tem 2021
- CVE-2021-2569531İzleyin
The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attack
YüksekCVSS 7,8İstismar yokEPSS %0teradici · pcoip21 Tem 2021
- CVE-2024-3321931İzleyin
An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and
YüksekCVSS 7,8İstismar yokEPSS %0asus · sabertooth x99 firmware22 May 2024
- CVE-2024-3321831İzleyin
An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate priv
YüksekCVSS 7,8İstismar yokEPSS %022 May 2024
- CVE-2026-850131İzleyin
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the
YüksekCVSS 7,8İstismar yokEPSS %0symantec · pc tools internet security1 Haz 2026
- CVE-2024-3322131İzleyin
An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and
YüksekCVSS 7,8İstismar yokEPSS %022 May 2024
- CVE-2025-4776131İzleyin
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3,
YüksekCVSS 7,8İstismar yokEPSS %0fortinet · forticlient18 Kas 2025
- CVE-2025-2612529İzleyin
An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate pri
YüksekCVSS 7,3Kavram kanıtıEPSS %117 Mar 2025
- CVE-2025-806129İzleyin
A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Leno
YüksekCVSS 7,3Kavram kanıtıEPSS %0lenovo · dispatcher 3.0 driver11 Eyl 2025