CVE-2024-39251

An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending crafted IOCTL requests.
Configurations

No configuration.

History

11 Jul 2024, 15:06

Type Values Removed Values Added
CWE CWE-782
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 10.0

02 Jul 2024, 12:09

Type Values Removed Values Added
Summary
  • (es) Un problema en el componente ControlCenter.sys/ControlCenter64.sys de ThundeRobot Control Center v2.0.0.10 permite a los atacantes acceder a información confidencial, ejecutar código arbitrario o escalar privilegios mediante el envío de solicitudes IOCTL manipuladas.

01 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-01 19:15

Updated : 2024-07-11 15:06


NVD link : CVE-2024-39251

Mitre link : CVE-2024-39251

CVE.ORG link : CVE-2024-39251


JSON object : View

Products Affected

No product.

CWE
CWE-782

Exposed IOCTL with Insufficient Access Control