CWE-782Variant1 in KEV

Exposed IOCTL with Insufficient Access Control

Draft in the CWE catalog · 30 CVEs mapped

30
CVEs mapped
1
In KEV
7.1
Median CVSS
What it is

The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Recent examples
7.1cvss
CVE-2026-80117

CVE-2026-80117 - HIGH Severity Vulnerability

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on exposed IOCTLs. Attackers can obtain a device handle and write to sensitive ports including the PS/2 controller port, CPU reset ports, CMOS configuration ports, and interrupt controller ports to cause an immediate system reset or other hardware-level manipulation from a standard user account.

HIGHno explanation yet
0%
epss
7.8cvss
CVE-2026-80116

CVE-2026-80116 - HIGH Severity Vulnerability

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address.

HIGHno explanation yet
0%
epss
6.1cvss
CVE-2026-80115

CVE-2026-80115 - MEDIUM Severity Vulnerability

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed IOCTLs with insufficient blocklist enforcement. Attackers can exploit the unrestricted write IOCTL to zero out the system call handler MSR, causing an immediate unrecoverable kernel crash on the next system call, or read security-sensitive MSRs used to locate kernel data structures.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-782
Abstraction
Variant
Structure
Simple
Status
Draft
References (1)