An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending crafted IOCTL requests.
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.