PT-2021-17905 · Asus · Asus Gputweak Ii
Published
2021-04-08
·
Updated
2022-07-12
·
CVE-2021-28685
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ASUS GPUTweak II versions prior to 2.3.0.3
Description:
The issue allows low-privileged users to interact directly with physical memory by calling certain driver routines that map physical memory into the virtual address space of the calling process. It also enables interaction with MSR registers, which could allow low-privileged users to achieve NT AUTHORITYSYSTEM privileges via a DeviceIoControl.
Recommendations:
For versions prior to 2.3.0.3, update to version 2.3.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the AsIO2 64.sys and AsIO2 32.sys drivers to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asus Gputweak Ii