PT-2018-14500 · Asus · Asus Aura Sync

Publicado

2018-12-26

·

Atualizado

2020-08-24

·

CVE-2018-18536

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS Aura Sync versions 1.07.22 and earlier
Description The issue concerns the exposure of functionality to read and write data from and to IO ports through the GLCKIo and Asusgio low-level drivers. This could potentially be leveraged to run code with elevated privileges.
Recommendations For versions 1.07.22 and earlier, update to a version later than 1.07.22 to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-18536

Produtos afetados

Asus Aura Sync