CVE-2026-4483: High severity MOXA MxGeneralIo vulnerability
An exposed IOCTL with an insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for Moxa’s industrial x86 computers. The affected utility, MxGeneralIo, exposes IOCTL methods that permit direct read and write access to MSR and system memory. A local attacker with high privileges could abuse these interfaces to perform unauthorized operations. Successful exploitation may result in privilege escalation on Windows 7 systems or cause a system crash (BSoD) on Windows 10 and 11 systems, leading to a denial-of-service condition. The vulnerability could slightly affect the confidentiality and integrity of the device, but availability might be heavily impacted. No impact to the subsequent system has been identified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4483?
CVE-2026-4483 has a high severity rating of 7 on the CVSS scale.
How do I fix CVE-2026-4483?
To mitigate CVE-2026-4483, it is recommended to update the MxGeneralIo utility to the latest version provided by Moxa.
What type of vulnerability is CVE-2026-4483?
CVE-2026-4483 is an insufficient access control vulnerability associated with exposed IOCTL methods.
What can a local attacker do with CVE-2026-4483?
A local attacker can exploit CVE-2026-4483 to gain unauthorized read and write access to MSR and system memory.
Which software is affected by CVE-2026-4483?
CVE-2026-4483 affects the MxGeneralIo utility in Moxa’s industrial x86 computers.