cve/2023/CVE-2023-35841.md

19 lines
964 B
Markdown
Raw Normal View History

2024-05-28 08:49:17 +00:00
### [CVE-2023-35841](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-35841)
![](https://img.shields.io/static/v1?label=Product&message=WinFlash%20Driver&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%204.5.0.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-732%20Incorrect%20Permission%20Assignment%20for%20Critical%20Resource&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-782%20Exposed%20IOCTL%20with%20Insufficient%20Access%20Control&color=brighgreen)
### Description
Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
### POC
#### Reference
- https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html
#### Github
No PoCs found on GitHub currently.