Description
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.
Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Published: 2026-07-03
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unchecked quantity parameter in the ASUS AI Suite 3 driver allows a local user to craft IOCTL requests that read or write memory outside the intended bounds, enabling escalated privileges. The flaw is identified as CWE‑1284 and permits the local attacker to access unintended memory regions through the driver.

Affected Systems

Any installation of ASUS AI Suite 3 that includes the vulnerable driver module is at risk. Version details were not specified, so the vulnerability may affect all current releases until a fix is released.

Risk and Exploitability

The vulnerability scores a CVSS of 8.5, indicating high severity, while the EPSS score of <1% suggests a low exploitation likelihood. It is not listed in the CISA KEV catalog. Since exploitation requires local access, the attack vector is a local user capable of sending crafted IOCTL requests to the driver.

Generated by OpenCVE AI on July 22, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest ASUS AI Suite 3 driver if available, or uninstall the program to remove the vulnerable component.
  • If a newer driver is not yet released, disable or remove the AI Suite 3 driver module from the kernel to eliminate the attack surface.
  • Restrict local user privileges so that only trusted administrators can run AI Suite 3 and issue IOCTL commands, limiting potential exploitation.

Generated by OpenCVE AI on July 22, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unchecked Quantity in ASUS AI Suite 3 Driver Enables Local Privilege Escalation

Fri, 17 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation. ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.

Wed, 15 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Driver IOCTL Memory Boundary Issue Enables Local Privilege Escalation in ASUS AI Suite 3

Mon, 13 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Driver IOCTL Memory Boundary Issue Enables Local Privilege Escalation in ASUS AI Suite 3

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IOCTL Out-of-Bounds in ASUS AI Suite 3

Sat, 11 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IOCTL Out-of-Bounds in ASUS AI Suite 3

Fri, 10 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Validation of Input Quantity in ASUS AI Suite 3 Driver Causing Local Privilege Escalation

Thu, 09 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Validation of Input Quantity in ASUS AI Suite 3 Driver Causing Local Privilege Escalation

Thu, 09 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Out‑of‑Bounds IOCTL Access in ASUS AI Suite 3

Wed, 08 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Out‑of‑Bounds IOCTL Access in ASUS AI Suite 3

Wed, 08 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Quantity Validation in ASUS AI Suite 3 Driver

Tue, 07 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Quantity Validation in ASUS AI Suite 3 Driver

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Improper Quantity Validation in ASUS AI Suite 3 Driver Allows Local Privilege Escalation

Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Quantity Validation in ASUS AI Suite 3 Driver Allows Local Privilege Escalation

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Validation of Input Quantity Allows Privilege Escalation via IOCTL in ASUS AI Suite 3 Driver

Sun, 05 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Validation of Input Quantity Allows Privilege Escalation via IOCTL in ASUS AI Suite 3 Driver

Sun, 05 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in ASUS AI Suite 3 Driver due to Improper Quantity Validation

Sat, 04 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in ASUS AI Suite 3 Driver due to Improper Quantity Validation

Sat, 04 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Input Validation in ASUS AI Suite 3

Sat, 04 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Input Validation in ASUS AI Suite 3

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Validation in ASUS AI Suite 3

Fri, 03 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Validation in ASUS AI Suite 3

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.
First Time appeared Asus
Asus ai Suite 3
Weaknesses CWE-1284
CPEs cpe:2.3:a:asus:ai_suite_3:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus ai Suite 3
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-17T06:00:27.417Z

Reserved: 2026-05-19T05:59:50.869Z

Link: CVE-2022-4989

cve-icon Vulnrichment

Updated: 2026-07-06T17:33:27.630Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input