Описание
DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
Ссылки
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- ExploitMailing ListThird Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.7.0 (исключая)
Одновременно
cpe:2.3:a:asus:device_activation:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00281
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-427
Связанные уязвимости
github
больше 3 лет назад
DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
EPSS
Процентиль: 51%
0.00281
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-427