CVE-2019-17603
Last modified
CVE-2019-17603 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asus | Aura Sync | <= 1.07.71 |
References
- https://zer0-day.pw/2020-06/asus-aura-sync-stack-based-buffer-overflow/Exploit, Third Party Advisory
- https://zer0-day.pw/2020-06/asus-aura-sync-stack-based-buffer-overflow/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17603?
How severe is CVE-2019-17603?
How do I fix CVE-2019-17603?
Are you affected by CVE-2019-17603?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
