The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Volume of CVEs assigned to CWE-782 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21551HIGH Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local aut | May 4, 2021 | 7.8 | 95 | YES | YES |
CVE-2026-36355HIGH The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5) | May 5, 2026 | 7.7 | 45 | NO | YES |
CVE-2025-7771HIGH ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure imple | Aug 6, 2025 | 8.7 | 45 | NO | YES |
CVE-2026-9492HIGH The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local a | Jul 13, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-8797HIGH An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM | Jun 26, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-57851HIGH MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical | Jul 7, 2026 | 7.8 | 34 | NO | NO |
CVE-2019-25764HIGH **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitr | Jul 17, 2026 | 7.3 | 32 | NO | NO |
CVE-2026-8501HIGH Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and i | Jun 1, 2026 | 7.8 | 32 | NO | NO |
CVE-2024-39251CRITICAL An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or | Jul 1, 2024 | 10.0 | 30 | NO | NO |
CVE-2024-32370CRITICAL An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mli | May 7, 2024 | 9.8 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.