ZeroHour

CVE-2023-35841

PoC
CVSS 3.1
7.8 high
EPSS
<1%p29
Published
()
Modified
Description

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

Vendors
phoenixtech
Products
winflash
Weakness
CWE-732, CWE-782
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news