PT-2024-22816 · Unknown · Cg6Kwin2K.Sys
Takahiro Haruyama
·
Published
2024-03-24
·
Updated
2024-11-07
·
CVE-2024-29216
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
cg6kwin2k.sys versions prior to 2.1.7.0
Description
The issue is related to an exposed IOCTL with insufficient access control in the cg6kwin2k.sys driver. This allows a user without administrator privileges to send a specific IOCTL request and perform I/O to arbitrary hardware ports or physical addresses, potentially resulting in the erasure or alteration of firmware.
Recommendations
For versions prior to 2.1.7.0, update to version 2.1.7.0 or later to secure the system. As a temporary workaround, consider restricting access to the IOCTL handler to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cg6Kwin2K.Sys