Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-522 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-11-07T16:54:34.686Z
Reserved: 2024-03-19T01:48:02.072Z
Link: CVE-2024-29216
Updated: 2024-08-02T01:10:55.351Z
Status : Deferred
Published: 2024-03-25T07:15:50.750
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-29216
No data.
OpenCVE Enrichment
No data.
Weaknesses