CVE-2022-44898
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aReferences
http://packetstormsecurity.com/files/174447/MsIo64-LOLDriver-Memory-Corruption.htmlhttps://heegong.github.io/posts/ASUS-AuraSync-Kernel-Stack-Based-Buffer-Overflow-Local-Privilege-Escalation/https://www.asus.com/campaign/aura/us/download.phphttps://www.asus.com/content/ASUS-Product-Security-Advisory/