CVE-2024-29216

Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.
Configurations

No configuration.

History

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://jvn.jp/en/vu/JVNVU90671953/ - () https://jvn.jp/en/vu/JVNVU90671953/ -
References () https://sangomakb.atlassian.net/wiki/spaces/DVC/pages/45351279/Natural+Access+Software+Download - () https://sangomakb.atlassian.net/wiki/spaces/DVC/pages/45351279/Natural+Access+Software+Download -

07 Nov 2024, 17:35

Type Values Removed Values Added
CWE CWE-522
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

25 Mar 2024, 13:47

Type Values Removed Values Added
Summary
  • (es) Existe un IOCTL expuesto con un problema de control de acceso insuficiente en cg6kwin2k.sys anterior a 2.1.7.0. Al enviar una solicitud IOCTL específica, un usuario sin privilegios de administrador puede realizar E/S en un puerto de hardware o dirección física arbitraria, lo que resulta en el borrado o alteración del firmware.

25 Mar 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-25 07:15

Updated : 2024-11-21 09:07


NVD link : CVE-2024-29216

Mitre link : CVE-2024-29216

CVE.ORG link : CVE-2024-29216


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials