7.8
CVE-2024-33219
- EPSS 0.16%
- Veröffentlicht 22.05.2024 15:15:28
- Zuletzt bearbeitet 18.04.2025 16:05:10
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asus ≫ Sabertooth X99 Firmware Version1.0.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.376 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-782 Exposed IOCTL with Insufficient Access Control
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.