VariantDraft
CWE-782Exposed IOCTL with Insufficient Access Control
Category: other
Description
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Common consequences· 1
- Integrity / Availability / Confidentiality — Varies by ContextAttackers can invoke any functionality that the IOCTL offers. Depending on the functionality, the consequences may include code execution, denial-of-service, and theft of data.
Potential mitigations· 1
- [Architecture and Design]In Windows environments, use proper access control for the associated device or device namespace. See References.
References
Compliance frameworks addressing this (incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | cis_v8-8 | 100% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Dell dbutil Driver Insufficient Access Control Vulnerabilitykev-cve-2021-21551 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.