Description
Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
Problem types
CWE-732 Incorrect Permission Assignment for Critical Resource
CWE-782 Exposed IOCTL with Insufficient Access Control
Product status
Any version before 4.5.0.0
Credits
Takahiro Haruyama of Broadcom 
References
www.phoenix.com/security-notifications/cve-2023-35841/
blogs.vmware.com/...0/hunting-vulnerable-kernel-drivers.html
jvn.jp/en/vu/JVNVU93886750/index.html
phoenixtech.com/...ix-security-notifications/cve-2023-35841/
blogs.vmware.com/...0/hunting-vulnerable-kernel-drivers.html
jvn.jp/en/vu/JVNVU93886750/index.html