Asus Aura Sync vulnerabilities
3 known vulnerabilities affecting asus/aura_sync.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2019-25764P3HIGHCVSS 7.3fixed in 1.07.842026-07-17
CVE-2019-25764 [HIGH] CWE-782 CVE-2019-25764: **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC
**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.
Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more info
nvd
CVE-2022-44898P3HIGHCVSS 7.8≤ 1.07.792022-12-14
CVE-2022-44898 [HIGH] CWE-787 CVE-2022-44898: The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCT
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.
nvd
CVE-2019-17603P3HIGHCVSS 7.8≤ 1.07.712020-06-02
CVE-2019-17603 [HIGH] CWE-787 CVE-2019-17603: Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
nvd