Description
** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation.
Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Published: 2026-07-03
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper validation of a quantity parameter in an IOCTL handler within ASUS AI Suite 3. Because the driver does not enforce bounds on the requested memory block size, a local user can craft an IOCTL request that reads or writes beyond the intended boundaries, accessing restricted memory and elevating privileges. This flaw represents an unchecked input validation weakness (CWE‑1284). The outcome is that a local attacker who can execute code on the machine may gain higher privileges, enabling local privilege escalation.

Affected Systems

The vulnerability affects ASUS AI Suite 3. No specific version information is provided, so all releases of the product may be vulnerable until a patched version is released.

Risk and Exploitability

The CVSS score of 7.3 indicates a medium‑to‑high severity risk. The EPSS score of < 1% indicates a very low but non not listed KEV, suggesting no confirmed active exploited only by users or processes that can send crafted IOCTL requests; however, the potential for privilege escalation remains significant where such local privileges are not tightly controlled.

Generated by OpenCVE AI on July 21, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ASUS AI Suite 3 update that corrects the IOCTL quantity validation flaw.
  • Reboot the system to load the patched driver so the fix takes effect immediately. If the driver cannot be updated, uninstall or disable the AI Suite 3 driver to block access to the vulnerable IOCTL interface.
  • Enforce least privilege by restricting local user accounts from executing the AI Suite 3 driver or from sending IOCTL requests to the kernel.

Generated by OpenCVE AI on July 21, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 21 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local privilege escalation via IOCTL quantity validation in ASUS AI Suite 3

Fri, 17 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsanitized IOCTL Quantity in ASUS AI Suite 3

Mon, 13 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Unsanitized IOCTL Quantity in ASUS AI Suite 3

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Quantity Validation in ASUS AI Suite 3

Sat, 11 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Improper IOCTL Quantity Validation in ASUS AI Suite 3

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Thu, 09 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Tue, 07 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Leading to Privilege Escalation in ASUS AI Suite 3

Mon, 06 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Leading to Privilege Escalation in ASUS AI Suite 3

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity Leading to Privilege Escalation via ASUS AI Suite 3 Driver

Mon, 06 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity Leading to Privilege Escalation via ASUS AI Suite 3 Driver

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Quantity Validation in ASUS AI Suite 3 Driver Allows Local Privilege Escalation

Sun, 05 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Quantity Validation in ASUS AI Suite 3 Driver Allows Local Privilege Escalation

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity in IOCTL Allows Local Privilege Escalation in ASUS AI Suite 3

Sat, 04 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Validation of Specified Quantity in IOCTL Allows Local Privilege Escalation in ASUS AI Suite 3

Sat, 04 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Allows Local Privilege Escalation in ASUS AI Suite 3

Sat, 04 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper IOCTL Quantity Validation Allows Local Privilege Escalation in ASUS AI Suite 3

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Fri, 03 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IOCTL Quantity Validation in ASUS AI Suite 3

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Description ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restricted memory blocks via crafted IOCTL requests, leading to privilege escalation.
First Time appeared Asus
Asus ai Suite 3
Weaknesses CWE-1284
CPEs cpe:2.3:a:asus:ai_suite_3:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus ai Suite 3
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-17T06:00:36.108Z

Reserved: 2026-05-19T06:00:30.357Z

Link: CVE-2022-4990

cve-icon Vulnrichment

Updated: 2026-07-06T15:41:50.388Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:30:04Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input