PT-2024-7972 · Asus · Asus Gputweak Ii

Driverhunter

·

Published

2024-05-22

·

Updated

2024-08-29

·

CVE-2024-33223

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ASUS GPU TweakII version 1.4.5.2
Description The issue is related to the component IOMap64.sys of ASUS GPU TweakII, which allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests. This is due to insecure privilege management. The exploitation of this issue can enable an attacker to elevate their privileges.
Recommendations For version 1.4.5.2, consider disabling the IOMap64.sys component until a patch is available to prevent potential privilege escalation and arbitrary code execution. Restrict access to the IOCTL requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-09485
CVE-2024-33223

Affected Products

Asus Gputweak Ii