PT-2020-14117 · Asus · Asus Screenpad2 Upgrade Tool+2

Published

2020-07-20

·

Updated

2020-07-29

·

CVE-2020-15009

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ASUS ScreenPad2 Upgrade Tool versions 1.0.3
Description The issue allows for unsigned code execution with no additional restrictions when a user places an application at a specific path with a particular file name, potentially affecting ASUS PCs with ScreenPad 1.0, such as UX450FDX, UX550GDX, and UX550GEX models.
Recommendations For version 1.0.3, consider restricting access to the AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe executables until a patch is available. Avoid placing applications at the particular path with the specific file name that could lead to unsigned code execution.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15009

Affected Products

Asus Screenpad2 Upgrade Tool
Asusscreenxpertservicec.Exe
Screenxpertupgradeservicemanager.Exe