PT-2020-14117 · Asus · Asus Screenpad2 Upgrade Tool+2
Published
2020-07-20
·
Updated
2020-07-29
·
CVE-2020-15009
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ASUS ScreenPad2 Upgrade Tool versions 1.0.3
Description
The issue allows for unsigned code execution with no additional restrictions when a user places an application at a specific path with a particular file name, potentially affecting ASUS PCs with ScreenPad 1.0, such as UX450FDX, UX550GDX, and UX550GEX models.
Recommendations
For version 1.0.3, consider restricting access to the
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe executables until a patch is available. Avoid placing applications at the particular path with the specific file name that could lead to unsigned code execution.Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Screenpad2 Upgrade Tool
Asusscreenxpertservicec.Exe
Screenxpertupgradeservicemanager.Exe