CVE-2018-10710: High severity asrock a-tuning vulnerability
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10710?
CVE-2018-10710 has a critical severity rating due to its potential for local privilege escalation.
How do I fix CVE-2018-10710?
To fix CVE-2018-10710, update your affected ASRock software to the latest versions: A-Tuning to v3.0.210, F-Stream to v3.0.210, RestartToUEFI to v1.0.6.2, and RGBLED to v1.0.35.1.
What systems are affected by CVE-2018-10710?
CVE-2018-10710 affects ASRock RGBLED, A-Tuning, F-Stream, and RestartToUEFI software versions prior to the specified updates.
Can CVE-2018-10710 be exploited remotely?
No, CVE-2018-10710 requires local access to the system for exploitation.
What type of threat does CVE-2018-10710 pose?
CVE-2018-10710 poses a threat of local privilege escalation, allowing attackers to gain elevated access on the machine.