Impact
The ASUS AURA SYNC driver contains a flaw in its IOCTL handling that allows a local user to bypass the driver’s verification process and issue arbitrary IOCTLs. This bypass can enable the user to perform privileged operations, directly resulting in local privilege escalation and compromising system security. The weakness corresponds to CWE‑782 (Insufficient Access Control).
Affected Systems
ASUS AURA SYNC driver on devices running the affected firmware or driver versions. The specific version list is not provided, and the only vendor noted is ASUS. Referencing the advisory, the issue applies to legacy ASUS drivers that have not yet been updated.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that exploitation is unlikely but still possible in the short term, especially on systems where the driver remains unpatched. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is a local user with access to the device that can execute custom IOCTL commands. No network exploitation or remote access is described, so the threat model remains confined to local attackers with the ability to run code on the host.
OpenCVE Enrichment