Vulnerabilidades em ASUS

168 resultados
Análise Vexday

Com 137 CVEs catalogadas, o portfólio de vulnerabilidades da ASUS apresenta uma taxa de exploração ativa 3,2 vezes acima da média geral do catálogo CISA KEV, o que indica que, proporcionalmente, as falhas nesse ecossistema têm maior chance de serem weaponizadas do que o esperado para vendors de porte similar. O tipo de falha mais recorrente é CWE-120 (buffer overflow clássico), uma classe de vulnerabilidade que frequentemente viabiliza execução remota de código e que exige atenção reforçada em processos de desenvolvimento e atualização de firmware. A CVE mais perigosa em exploração ativa no momento, CVE-2023-39780, registra um escore EPSS de 0,3216, sinalizando probabilidade relevante de exploração contínua e justificando priorização imediata de correção. Com 12 CVEs críticas e 7 novas entradas nos últimos 90 dias, equipes de segurança que operam ativos ASUS devem manter ciclos de patching curtos e monitorar ativamente indicadores de comprometimento associados às falhas confirmadas no KEV.

CVE-2026-7480HIGHAn Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate priviEPSS 0.1%CVE-2025-12793HIGHAn uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a EPSS 0.1%CVE-2025-59373HIGHA local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when aEPSS 0.1%CVE-2025-9337MEDIUMA null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, whiEPSS 0.1%CVE-2022-4990HIGH** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypaEPSS 0.1%CVE-2026-1878MEDIUMAn Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SEPSS 0.1%CVE-2025-9338HIGHA improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered byEPSS 0.1%CVE-2025-11775MEDIUMAn out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crEPSS 0.1%CVE-2019-25764HIGH**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass theEPSS 0.1%CVE-2026-8917HIGHUntrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to wrEPSS 0.1%CVE-2026-8920HIGHImproper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service alloEPSS 0.1%CVE-2026-19398MEDIUMAn out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSEPSS 0.1%CVE-2025-13348HIGHAn improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered bEPSS 0.1%CVE-2026-75810MEDIUMExposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authenticatiEPSS 0.1%CVE-2026-75808MEDIUMAllocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition througEPSS 0.1%CVE-2026-75809MEDIUMExposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device funcEPSS 0.1%CVE-2025-15038MEDIUMAn Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an uEPSS 0.1%CVE-2026-75811MEDIUMImproper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration EPSS 0.1%CVE-2025-15037MEDIUMAn Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be trigEPSS 0.1%CVE-2026-6737LOWAn Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms anEPSS 0.1%