Impact
An unchecked quantity parameter in the ASUS AI Suite 3 driver allows a local user to craft IOCTL requests that read or write memory outside the intended bounds, enabling escalated privileges. The flaw is identified as CWE‑1284 and permits the local attacker to access unintended memory regions through the driver.
Affected Systems
Any installation of ASUS AI Suite 3 that includes the vulnerable driver module is at risk. Version details were not specified, so the vulnerability may affect all current releases until a fix is released.
Risk and Exploitability
The vulnerability scores a CVSS of 8.5, indicating high severity, while the EPSS score of <1% suggests a low exploitation likelihood. It is not listed in the CISA KEV catalog. Since exploitation requires local access, the attack vector is a local user capable of sending crafted IOCTL requests to the driver.
OpenCVE Enrichment