PT-2024-25162 · Wistron · Tbt Force Power Control

Driverhunter

·

Published

2024-05-22

·

Updated

2024-08-22

·

CVE-2024-33226

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Wistron Corporation TBT Force Power Control version 1.0.0.0
Description An issue in the component Access64.sys allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Recommendations For version 1.0.0.0, consider restricting access to the Access64.sys component to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the vulnerable component to send crafted IOCTL requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-33226

Affected Products

Tbt Force Power Control