Threats Tagged 'cwe-782'
View all threats tagged with 'cwe-782'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-782'
Click on any threat for detailed analysis and mitigation recommendations
0 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. Join the discussion | CVE Database V5 | 09/08/2026, 02:03:17 UTC Added: 09/08/2026, 02:37:42 UTC |
0 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information. Join the discussion | CVE Database V5 | 09/08/2026, 02:02:49 UTC Added: 09/08/2026, 02:37:42 UTC |
0 Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. Join the discussion | CVE Database V5 | 09/08/2026, 02:01:14 UTC Added: 09/08/2026, 02:37:42 UTC |
0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address parameter in an exposed IOCTL handler. Attackers can obtain a device handle and supply an arbitrary 64-bit physical address with a bit index to invoke MmMapIoSpace and clear bits in kernel code pages or page table entries, enabling local privilege escalation or system compromise. Join the discussion | GCVE Database | 09/04/2026, 18:33:38 UTC Added: 09/05/2026, 14:24:56 UTC |
0 A local privilege escalation vulnerability exists in Unistal Systems Pvt. Ltd. Protegent 360 version 2.0.0.4. The issue involves the kernel driver pgsecdl.sys, which allows a local attacker to escalate privileges. This vulnerability has a high severity rating with a CVSS score of 7.8, indicating significant impact on confidentiality, integrity, and availability if exploited. Join the discussion | GCVE Database | 07/23/2026, 00:00:00 UTC Added: 07/23/2026, 22:51:59 UTC |
0 CVE-2026-9492 is an improper access control vulnerability in the MBStorage DRAM lighting control module of Gigabyte Control Center. Authenticated local attackers can send specific IOCTL commands via the MyPortIO_x64.sys driver, allowing arbitrary physical memory read/write and kernel-level privilege escalation. The vulnerability has a high severity score of 8.5. No patch or official remediation has been confirmed yet. Join the discussion | CVE Database V5 | 07/13/2026, 03:41:32 UTC Added: 07/13/2026, 04:05:09 UTC |
0 An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges. Join the discussion | CVE Database V5 | 06/26/2026, 04:14:19 UTC Added: 06/26/2026, 05:01:13 UTC |
0 CVE-2025-15641 is a vulnerability in the Netskope Client for Windows where a malicious insider with administrative privileges can send crafted IOCTL requests to the driver. This can bypass all anti-tampering protections for the Netskope Client. The issue affects all versions below R138. The vulnerability has a medium severity with a CVSS score of 6.8. Join the discussion | CVE Database V5 | 06/17/2026, 01:31:51 UTC Added: 06/17/2026, 02:00:35 UTC |
0 CVE-2026-8501 is a high-severity vulnerability in the Symantec PC Tools Internet Security product. It involves improper access control in the PCTCore64.sys Windows kernel driver, allowing local user-mode processes to access privileged IOCTL handlers via the PCTCoreDriver WDM device interface. This can enable a local attacker with access to the driver to perform sensitive and privileged operations on the affected system. There is no confirmed patch or official remediation available at this time, and no known exploits have been reported in the wild. Join the discussion | CVE Database V5 | 06/01/2026, 16:25:11 UTC Added: 06/01/2026, 17:04:39 UTC |
0 An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and obtain restricted touchpad information or render the touchpad unusable via crafted IOCTL requests.Refer to the ' Security Update for ASUS Precision Touchpad ' section on the ASUS Security Advisory for more information. Join the discussion | CVE Database V5 | 05/08/2026, 02:00:26 UTC Added: 05/08/2026, 02:36:23 UTC |
Showing 1 to 10 of 14 results