Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
History

Thu, 25 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Phoenixtech
Phoenixtech winflash
CPEs cpe:2.3:a:phoenixtech:winflash:*:*:*:*:*:windows:*:*
Vendors & Products Phoenixtech
Phoenixtech winflash

Mon, 28 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
Description Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0. Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Phoenix

Published: 2024-05-14T14:56:14.743Z

Updated: 2025-07-28T20:49:33.663Z

Reserved: 2023-06-19T00:35:50.974Z

Link: CVE-2023-35841

cve-icon Vulnrichment

Updated: 2024-08-02T16:30:45.376Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T16:15:36.953

Modified: 2025-09-25T17:10:34.097

Link: CVE-2023-35841

cve-icon Redhat

No data.