CVE-2023-35841: Phoenixtech Winflash

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

Affected products

  • Phoenixtech Winflash: before 4.5.0.0 (fixed in 4.5.0.0)

Published 2024-05-14. Last modified 2026-06-17.