7.8
CVE-2023-35841
- EPSS 0.16%
- Veröffentlicht 14.05.2024 16:15:36
- Zuletzt bearbeitet 25.09.2025 17:10:34
- Quelle 22d9ba52-f336-4b0d-bf1f-0efbdc
- CVE-Watchlists
- Unerledigt
Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phoenixtech ≫ Winflash SwPlatformwindows Version < 4.5.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.366 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CWE-782 Exposed IOCTL with Insufficient Access Control
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.