Common Weakness Enumeration

    CWE Definition / CWE-782

    CWE-782: Exposed IOCTL with Insufficient Access Control

    The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

    Published:15 Jul 2009
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-749: Exposed Dangerous Method or Function

    CWE-781: Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code