PT-2024-22816 · Unknown · Cg6Kwin2K.Sys

Takahiro Haruyama

·

Published

2024-03-24

·

Updated

2024-11-07

·

CVE-2024-29216

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions cg6kwin2k.sys versions prior to 2.1.7.0
Description The issue is related to an exposed IOCTL with insufficient access control in the cg6kwin2k.sys driver. This allows a user without administrator privileges to send a specific IOCTL request and perform I/O to arbitrary hardware ports or physical addresses, potentially resulting in the erasure or alteration of firmware.
Recommendations For versions prior to 2.1.7.0, update to version 2.1.7.0 or later to secure the system. As a temporary workaround, consider restricting access to the IOCTL handler to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-29216

Affected Products

Cg6Kwin2K.Sys