PT-2022-27329 · Asus · Asus Aura Sync
Heechan Kim
+1
·
Published
2022-12-14
·
Updated
2023-09-02
·
CVE-2022-44898
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Asus Aura Sync versions through v1.07.79
Description
The issue concerns the MsIo64.sys component, which does not properly validate input to certain IOCTL requests, specifically 0x80102040, 0x80102044, 0x80102050, and 0x80102054. This allows attackers to trigger memory corruption, potentially causing a Denial of Service (DoS) or escalating privileges via crafted IOCTL requests.
Recommendations
For Asus Aura Sync versions through v1.07.79, consider disabling the MsIo64.sys component until a patch is available to prevent potential exploitation. Restrict access to the vulnerable IOCTL requests to minimize the risk of memory corruption and subsequent DoS or privilege escalation.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Aura Sync