7.8
CVE-2024-33219
- EPSS 0.12%
- Veröffentlicht 22.05.2024 15:15:28
- Zuletzt bearbeitet 18.04.2025 16:05:10
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Asus ≫ Sabertooth X99 Firmware Version1.0.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.12% | 0.314 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-782 Exposed IOCTL with Insufficient Access Control
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.