Fallos del tipo CWE-782

48 resultados

IOCTL exposto com controle de acesso insuficiente

Ocorre quando um driver ou componente do kernel expõe uma operação IOCTL (interface de controle de dispositivo) sem validar adequadamente as permissões do processo que a chama. Um usuário sem privilégios pode executar operações administrativas ou acessar dados sensíveis que deveriam estar restritos, comprometendo a integridade do sistema.

Ejemplo

Um driver de hardware permite que qualquer processo no sistema chame um IOCTL para resetar configurações críticas ou ler registros de segurança sem verificar se o chamador é root ou pertence a um grupo autorizado. Um usuário comum consegue invocar essa operação e desabilitar proteções ou vazar informações do kernel.

Cómo mitigar

Sempre validar o UID/GID do processo chamador e o contexto de segurança (capabilities do Linux, ACLs, etc.) antes de executar qualquer IOCTL. Implementar uma lista explícita de operações permitidas por nível de privilégio e rejeitar tudo que não estiver na whitelist. Usar ferramentas como `cap_has_capability()` no kernel para verificar permissões específicas.

CVE-2026-4483HIGHAn exposed IOCTL with an  insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial xEPSS 0.3%CVE-2021-21786HIGHA privilege escalation vulnerability exists in the IOCTL 0x9c406144 handling of IOBit Advanced SystemCare Ultimate 14.2.0.220. A specially cEPSS 0.3%CVE-2021-25695The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attackEPSS 0.3%CVE-2024-33219HIGHAn issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges andEPSS 0.3%CVE-2024-33218HIGHAn issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privEPSS 0.2%CVE-2024-33222HIGHAn issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execuEPSS 0.2%CVE-2026-38764HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.2%CVE-2024-33221HIGHAn issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges andEPSS 0.2%CVE-2023-44976LOWHangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and possibly have unspecified other impact via DeEPSS 0.2%CVE-2026-38765HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sysEPSS 0.2%CVE-2026-38766HIGHAn issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 functionEPSS 0.2%CVE-2026-57851HIGHMSI KernCoreLib64.sys Privilege Escalation via IOCTL HandlersEPSS 0.2%CVE-2026-56129MEDIUMGeneric IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access contrEPSS 0.2%CVE-2025-15641MEDIUMNetskope Client Exposed IOCTL with Insufficient Access ControlsEPSS 0.2%CVE-2026-8501HIGHCVE-2026-8501EPSS 0.2%CVE-2025-47761HIGHAn Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, EPSS 0.2%CVE-2026-9492HIGHGIGABYTE|Gigabyte Control Center - Improper Access ControlEPSS 0.2%CVE-2026-8797HIGHAn access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitEPSS 0.1%CVE-2019-25764HIGH**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass theEPSS 0.1%CVE-2026-80116HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTLEPSS 0.1%