CWE-123Base1 in KEV

Write-what-where Condition

Draft in the CWE catalog · 41 CVEs mapped

41
CVEs mapped
1
In KEV
7.8
Median CVSS
What it is

Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Recent examples
8.8cvss
CVE-2026-81579

CVE-2026-81579 - HIGH Severity Vulnerability

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator shell, or gain full control over the system.

HIGHno explanation yet
0%
epss
6.0cvss
CVE-2026-20469

CVE-2026-20469 - MEDIUM Severity Vulnerability

In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533.

MEDIUMno explanation yet
0%
epss
7.4cvss
CVE-2026-47473

NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition

NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-123
Abstraction
Base
Structure
Simple
Status
Draft
References (2)