CVE-2019-25764
- EPSS 0.09%
- Veröffentlicht 17.07.2026 06:00:10
- Zuletzt bearbeitet 17.07.2026 18:10:29
**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-L...
CVE-2022-44898
- EPSS 0.37%
- Veröffentlicht 14.12.2022 15:15:10
- Zuletzt bearbeitet 22.04.2025 14:15:22
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalat...
CVE-2019-17603
- EPSS 0.73%
- Veröffentlicht 02.06.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:37
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kerne...