CWE-782: Exposed IOCTL with Insufficient Access Control
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
33 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-4196 — Avaya IP Office Web Control RCE Vulnerability
- CVE-2025-7771 — Code Execution / Escalation of Privileges in ThrottleStop
- CVE-2025-8061 — A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drive
- CVE-2025-47761 — An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7
- CVE-2026-9492 — GIGABYTE|Gigabyte Control Center - Improper Access Control
- CVE-2026-8797 — An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t
- CVE-2026-80116 — PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL
- CVE-2026-57851 — MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
- CVE-2024-0141 — NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level
- CVE-2019-25764 — **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a loca
- CVE-2026-4483 — An exposed IOCTL with an insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for
- CVE-2026-80117 — PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via DirectIo64.sys
- CVE-2026-80115 — PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR Write IOCTL
- CVE-2026-80113 — PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.sys IOCTL
- CVE-2025-15641 — Netskope Client Exposed IOCTL with Insufficient Access Controls
- CVE-2026-56129 — Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insuf
- CVE-2025-27535 — Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers
- CVE-2026-75809 — Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and d
- CVE-2026-16004 — Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary P
- CVE-2026-6737 — An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver se
Recently published
- CVE-2026-16003 — Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process i
- CVE-2026-16004 — Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary P
- CVE-2026-75809 — Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and d
- CVE-2026-80117 — PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via DirectIo64.sys
- CVE-2026-80116 — PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL
- CVE-2026-80115 — PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR Write IOCTL
- CVE-2026-80113 — PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.sys IOCTL
- CVE-2019-25764 — **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a loca
- CVE-2026-9492 — GIGABYTE|Gigabyte Control Center - Improper Access Control
- CVE-2026-57851 — MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
- CVE-2026-8797 — An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t
- CVE-2026-56129 — Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insuf
- CVE-2025-15641 — Netskope Client Exposed IOCTL with Insufficient Access Controls
- CVE-2026-6737 — An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver se
- CVE-2026-4483 — An exposed IOCTL with an insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for
- CVE-2025-27535 — Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers
- CVE-2025-47761 — An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7
- CVE-2025-8061 — A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drive
- CVE-2025-7771 — Code Execution / Escalation of Privileges in ThrottleStop
- CVE-2024-0141 — NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level