PT-2018-14500 · Asus · Asus Aura Sync

Published

2018-12-26

·

Updated

2020-08-24

·

CVE-2018-18536

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS Aura Sync versions 1.07.22 and earlier
Description The issue concerns the exposure of functionality to read and write data from and to IO ports through the GLCKIo and Asusgio low-level drivers. This could potentially be leveraged to run code with elevated privileges.
Recommendations For versions 1.07.22 and earlier, update to a version later than 1.07.22 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-18536

Affected Products

Asus Aura Sync