CVE-2022-44898
published 2022-12-14CVE-2022-44898: The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.37%
29.2th percentile
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asus | aura_sync | <= 1.07.79 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/174447/MsIo64-LOLDriver-Memory-Corruption.htmlhttps://heegong.github.io/posts/ASUS-AuraSync-Kernel-Stack-Based-Buffer-Overflow-Local-Privilege-Escalation/https://www.asus.com/campaign/aura/us/download.phphttps://www.asus.com/content/ASUS-Product-Security-Advisory/http://packetstormsecurity.com/files/174447/MsIo64-LOLDriver-Memory-Corruption.htmlhttps://heegong.github.io/posts/ASUS-AuraSync-Kernel-Stack-Based-Buffer-Overflow-Local-Privilege-Escalation/https://www.asus.com/campaign/aura/us/download.phphttps://www.asus.com/content/ASUS-Product-Security-Advisory/
2022-12-14
Published