Description
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation.
Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Published: 2026-07-03
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper validation of a quantity parameter in an IOCTL handler within ASUS AI Suite 3. Because the driver does not enforce bounds on the requested memory block size, a local user can craft an IOCTL request that reads or writes beyond the intended boundaries, accessing restricted memory and elevating privileges. This flaw represents an unchecked input validation weakness (CWE‑1284). The outcome is that a local attacker who can execute code on the machine may gain higher privileges, enabling local privilege escalation.

Affected Systems

The vulnerability affects ASUS AI Suite 3. No specific version information is provided, so all releases of the product may be vulnerable until a patched version is released.

Risk and Exploitability

The CVSS score of 7.3 indicates a medium‑to‑high severity risk. The EPSS score of < 1% indicates a very low but non zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw allows a local attacker with the ability to send crafted IOCTL requests to read or write out‑of‑bounds memory, potentially gaining elevated privileges. The attack vector is local and requires the attacker to be able to execute or interact with the AI Suite 3 driver.

Generated by OpenCVE AI on July 29, 2026 at 18:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ASUS AI Suite 3 update that corrects the IOCTL quantity validation flaw.
  • Reboot the system to load the patched driver so the fix takes effect immediately. If the driver cannot be updated, uninstall or disable the AI Suite 3 driver to block access to the vulnerable IOCTL interface.
  • Enforce least privilege by restricting local user accounts from executing the AI Suite 3 driver or sending IOCTL requests to the kernel.

Generated by OpenCVE AI on July 29, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 29 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation through Improper IOCTL Quantity Validation in ASUS AI Suite 3

Wed, 29 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Asus ai Suite
Vendors & Products Asus ai Suite

Sat, 25 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation through Improper IOCTL Quantity Validation in ASUS AI Suite 3

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local privilege escalation via IOCTL quantity validation in ASUS AI Suite 3

Tue, 21 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local privilege escalation via IOCTL quantity validation in ASUS AI Suite 3

Fri, 17 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsanitized IOCTL Quantity in ASUS AI Suite 3

Mon, 13 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsanitized IOCTL Quantity in ASUS AI Suite 3

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Quantity Validation in ASUS AI Suite 3

Sat, 11 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Quantity Validation in ASUS AI Suite 3

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Thu, 09 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Tue, 07 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Leading to Privilege Escalation in ASUS AI Suite 3

Mon, 06 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Leading to Privilege Escalation in ASUS AI Suite 3

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity Leading to Privilege Escalation via ASUS AI Suite 3 Driver

Mon, 06 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity Leading to Privilege Escalation via ASUS AI Suite 3 Driver

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Quantity Validation in ASUS AI Suite 3 Driver Allows Local Privilege Escalation

Sun, 05 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Quantity Validation in ASUS AI Suite 3 Driver Allows Local Privilege Escalation

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity in IOCTL Allows Local Privilege Escalation in ASUS AI Suite 3

Sat, 04 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity in IOCTL Allows Local Privilege Escalation in ASUS AI Suite 3

Sat, 04 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Allows Local Privilege Escalation in ASUS AI Suite 3

Sat, 04 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Allows Local Privilege Escalation in ASUS AI Suite 3

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Fri, 03 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation.
First Time appeared Asus
Asus ai Suite 3
Weaknesses CWE-1284
CPEs cpe:2.3:a:asus:ai_suite_3:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus ai Suite 3
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Ai Suite Ai Suite 3
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-17T06:00:36.108Z

Reserved: 2026-05-19T06:00:30.357Z

Link: CVE-2022-4990

cve-icon Vulnrichment

Updated: 2026-07-06T15:41:50.388Z

cve-icon NVD

Status : Deferred

Published: 2026-07-03T03:16:23.087

Modified: 2026-07-17T07:16:37.490

Link: CVE-2022-4990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T18:45:03Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input