Impact
The vulnerability arises from improper validation of a quantity parameter in an IOCTL handler within ASUS AI Suite 3. Because the driver does not enforce bounds on the requested memory block size, a local user can craft an IOCTL request that reads or writes beyond the intended boundaries, accessing restricted memory and elevating privileges. This flaw represents an unchecked input validation weakness (CWE‑1284). The outcome is that a local attacker who can execute code on the machine may gain higher privileges, enabling local privilege escalation.
Affected Systems
The vulnerability affects ASUS AI Suite 3. No specific version information is provided, so all releases of the product may be vulnerable until a patched version is released.
Risk and Exploitability
The CVSS score of 7.3 indicates a medium‑to‑high severity risk. The EPSS score of < 1% indicates a very low but non zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw allows a local attacker with the ability to send crafted IOCTL requests to read or write out‑of‑bounds memory, potentially gaining elevated privileges. The attack vector is local and requires the attacker to be able to execute or interact with the AI Suite 3 driver.
OpenCVE Enrichment