PT-2024-5165 · Asus · Asinshelp64.Sys+1

Published

2024-04-26

·

Updated

2024-10-25

·

CVE-2024-30804

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: ASUS Fan Xpert versions prior to 10013
Description: An issue in the DeviceIoControl component allows an attacker to execute arbitrary code via crafted IOCTL requests. The vulnerability is related to a buffer overflow in the AsInsHelp64.sys driver, which can be exploited to elevate privileges or disclose protected information.
Recommendations: For versions prior to 10013, update to version 10013 or later to resolve the issue. As a temporary workaround, consider restricting access to the DeviceIoControl component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05716
CVE-2024-30804

Affected Products

Asus Fan Xpert
Asinshelp64.Sys