PT-2018-14499 · Asus · Asus Aura Sync

Diego Juarez

·

Published

2018-12-26

·

Updated

2020-08-24

·

CVE-2018-18535

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS Aura Sync versions 1.07.22 and earlier
Description The issue in ASUS Aura Sync allows for the exposure of functionality to read and write Machine Specific Registers (MSRs), which could potentially be used to execute arbitrary ring-0 code.
Recommendations For versions 1.07.22 and earlier, update to a version later than 1.07.22 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-18535

Affected Products

Asus Aura Sync