Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-35841


Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.


Published

2024-05-14T16:15:36.953

Last Modified

2025-09-25T17:10:34.097

Status

Analyzed

Source

22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-732
    CWE-782

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application phoenixtech winflash < 4.5.0.0 Yes

References