CVE-2023-35841

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phoenixtech:winflash:*:*:*:*:*:windows:*:*

History

25 Sep 2025, 17:10

Type Values Removed Values Added
First Time Phoenixtech winflash
Phoenixtech
CPE cpe:2.3:a:phoenixtech:winflash:*:*:*:*:*:windows:*:*
References () https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html - () https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html - Exploit, Third Party Advisory
References () https://jvn.jp/en/vu/JVNVU93886750/index.html - () https://jvn.jp/en/vu/JVNVU93886750/index.html - Third Party Advisory
References () https://phoenixtech.com/phoenix-security-notifications/cve-2023-35841/ - () https://phoenixtech.com/phoenix-security-notifications/cve-2023-35841/ - Vendor Advisory
References () https://www.phoenix.com/security-notifications/cve-2023-35841/ - () https://www.phoenix.com/security-notifications/cve-2023-35841/ - Vendor Advisory

28 Jul 2025, 21:15

Type Values Removed Values Added
References
  • () https://phoenixtech.com/phoenix-security-notifications/cve-2023-35841/ -
Summary (en) Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0. (en) Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

21 Nov 2024, 08:08

Type Values Removed Values Added
References () https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html - () https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html -
References () https://jvn.jp/en/vu/JVNVU93886750/index.html - () https://jvn.jp/en/vu/JVNVU93886750/index.html -
References () https://www.phoenix.com/security-notifications/cve-2023-35841/ - () https://www.phoenix.com/security-notifications/cve-2023-35841/ -

14 May 2024, 19:18

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:15

Updated : 2025-09-25 17:10


NVD link : CVE-2023-35841

Mitre link : CVE-2023-35841

CVE.ORG link : CVE-2023-35841


JSON object : View

Products Affected

phoenixtech

  • winflash
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-782

Exposed IOCTL with Insufficient Access Control