Impact
The vulnerability arises from improper validation of a quantity parameter in an IOCTL handler within ASUS AI Suite 3. Because the driver does not enforce bounds on the requested memory block size, a local user can craft an IOCTL request that reads or writes beyond the intended boundaries, accessing restricted memory and elevating privileges. This flaw represents an unchecked input validation weakness (CWE‑1284). The outcome is that a local attacker who can execute code on the machine may gain higher privileges, enabling local privilege escalation.
Affected Systems
The vulnerability affects ASUS AI Suite 3. No specific version information is provided, so all releases of the product may be vulnerable until a patched version is released.
Risk and Exploitability
The CVSS score of 7.3 indicates a medium‑to‑high severity risk. The EPSS score of < 1% indicates a very low but non not listed KEV, suggesting no confirmed active exploited only by users or processes that can send crafted IOCTL requests; however, the potential for privilege escalation remains significant where such local privileges are not tightly controlled.
OpenCVE Enrichment