PT-2025-13436 · Asus · Asus System Analysis Service

Published

2025-03-28

·

Updated

2025-03-29

·

CVE-2025-2027

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ASUS System Analysis service (affected versions not specified)
Description A double free vulnerability has been identified, which can be triggered by sending specially crafted local RPC requests. This leads to the service crash and potentially memory manipulation in some rare circumstances.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2027

Affected Products

Asus System Analysis Service