Junglewise Threat Intelligence

CVE-2026-4483: Moxa MxGeneralIo insufficient access control in IOCTL

CVE-2026-4483 · Severity: info · CVSS 7 · Published 2026-04-08

Vendors: Moxa.

Executive brief

A security vulnerability exists in the MxGeneralIo utility used by Moxa industrial x86 computers, which are typically used in manufacturing, power, and transportation sectors. An attacker with high-level access could exploit this flaw to gain even higher system privileges or cause the computer to crash. This could lead to unauthorized control over the device or a complete service outage, potentially disrupting industrial operations.

Technical details

An exposed IOCTL (Input/Output Control) vulnerability (CWE-782) exists in the MxGeneralIo utility for Moxa industrial x86 computers. The utility fails to implement sufficient access controls on IOCTL methods that permit direct read and write access to Model-Specific Registers (MSR) and system memory. While the CVSS vector indicates a network attack vector, the advisory text specifies a local attacker with high privileges is required. Successful exploitation on Windows 7 systems can lead to privilege escalation, while on Windows 10 and 11 systems, it typically results in a Blue Screen of Death (BSoD), causing a denial-of-service condition. Moxa has released patches (v1.4.0 for Windows 7 and v1.5.0 for Windows 10/11) to address the issue.

Affected products

  • Moxa MxGeneralIo Windows 7: before v1.4.0; Windows 10: before v1.5.0; Windows 11: before v1.5.0

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References