Description
**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.

Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Published: 2026-07-17
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ASUS AURA SYNC driver contains a flaw in its IOCTL handling that allows a local user to bypass the driver’s verification process and issue arbitrary IOCTLs. This bypass can enable the user to perform privileged operations, directly resulting in local privilege escalation and compromising system security. The weakness corresponds to CWE‑782 (Insufficient Access Control).

Affected Systems

ASUS AURA SYNC driver on devices running the affected firmware or driver versions. The specific version list is not provided, and the only vendor noted is ASUS. Referencing the advisory, the issue applies to legacy ASUS drivers that have not yet been updated.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that exploitation is unlikely but still possible in the short term, especially on systems where the driver remains unpatched. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is a local user with access to the device that can execute custom IOCTL commands. No network exploitation or remote access is described, so the threat model remains confined to local attackers with the ability to run code on the host.

Generated by OpenCVE AI on July 31, 2026 at 00:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ASUS AURA SYNC driver to the latest version released by ASUS
  • Restrict local user access to the driver’s device node to only privileged users or remove unnecessary users from the group that has access
  • If an update is unavailable, consider disabling the AURA SYNC driver until an official fix is applied

Generated by OpenCVE AI on July 31, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 31 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unrestricted IOCTL in ASUS AURA SYNC Driver

Wed, 29 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unrestricted IOCTL in ASUS AURA SYNC Driver

Sun, 26 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Insufficient Access Control on ASUS AURA SYNC Driver Allows Local Privilege Escalation

Wed, 22 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Insufficient Access Control on ASUS AURA SYNC Driver Allows Local Privilege Escalation

Fri, 17 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description **UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus aura Sync
Weaknesses CWE-782
CPEs cpe:2.3:a:asus:aura_sync:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus aura Sync
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-17T10:10:36.305Z

Reserved: 2026-06-23T07:34:36.865Z

Link: CVE-2019-25764

cve-icon Vulnrichment

Updated: 2026-07-17T10:10:31.727Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:45:05Z

Weaknesses
  • CWE-782

    Exposed IOCTL with Insufficient Access Control