Impact
This vulnerability is an untrusted pointer dereference in several ASUS utility programs, triggered via an IOCTL call. The flaw permits a local attacker to write an arbitrary value to an arbitrary memory address. Because the affected utilities run with elevated privileges, successful exploitation can lead to privilege escalation and compromise of the system.
Affected Systems
The flaw affects ASUS"s AI Suite3, GPU Tweak III, GPUTweakII, and VGAdll software. The affected versions are unspecified; all installed versions are potentially vulnerable until patched.
Risk and Exploitability
A CVSS score of 8.4 indicates high severity. The EPSS score is not available, so the exact exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local – an attacker must be able to run code on the affected machine to issue the vulnerable IOCTL. Once the arbitrary write is achieved, privilege escalation to the utility’s process rights can occur.
OpenCVE Enrichment