CVE-2019-25764: High severity ASUS ASUS AURA SYNC driver vulnerability
UNSUPPORTED WHEN ASSIGNED Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.
Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25764?
The severity of CVE-2019-25764 is high, with a CVSS score of 7.3.
How does CVE-2019-25764 allow privilege escalation?
CVE-2019-25764 allows privilege escalation by exposing IOCTLs with insufficient access control in the ASUS AURA SYNC driver.
Who is affected by CVE-2019-25764?
Local users of the ASUS AURA SYNC driver are affected by CVE-2019-25764.
Is there a patch available for CVE-2019-25764?
There is no patch available for CVE-2019-25764 as it pertains to an unsupported driver.
What should users do to mitigate CVE-2019-25764?
Users should discontinue the use of the affected ASUS AURA SYNC driver to mitigate the risk associated with CVE-2019-25764.