PT-2021-17905 · Asus · Asus Gputweak Ii

Published

2021-04-08

·

Updated

2022-07-12

·

CVE-2021-28685

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ASUS GPUTweak II versions prior to 2.3.0.3
Description: The issue allows low-privileged users to interact directly with physical memory by calling certain driver routines that map physical memory into the virtual address space of the calling process. It also enables interaction with MSR registers, which could allow low-privileged users to achieve NT AUTHORITYSYSTEM privileges via a DeviceIoControl.
Recommendations: For versions prior to 2.3.0.3, update to version 2.3.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the AsIO2 64.sys and AsIO2 32.sys drivers to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-28685

Affected Products

Asus Gputweak Ii