Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-873m-q6f6-cfqx

Опубликовано: 14 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.

The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.

EPSS

Процентиль: 40%
0.00183
Низкий

7.8 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
nvd
около 3 лет назад

The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.

EPSS

Процентиль: 40%
0.00183
Низкий

7.8 High

CVSS3

Дефекты

CWE-787