CVE-2024-29216: Medium severity Unknown cg6kwin2k.sys vulnerability
Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29216?
CVE-2024-29216 has been rated as a high severity vulnerability due to the risk of arbitrary hardware access by unauthorized users.
How do I fix CVE-2024-29216?
To mitigate CVE-2024-29216, upgrade the cg6kwin2k.sys driver to version 2.1.7.0 or later.
What kind of access does CVE-2024-29216 allow?
CVE-2024-29216 allows a user without administrative privileges to perform I/O to arbitrary hardware ports or physical addresses.
Which software is affected by CVE-2024-29216?
CVE-2024-29216 affects the cg6kwin2k.sys driver versions prior to 2.1.7.0.
What are the potential consequences of CVE-2024-29216?
The potential consequences of CVE-2024-29216 include the ability to erase or alter firmware, which can lead to system instability or compromised security.