CVE-2018-10712: High severity asrock a-tuning vulnerability
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10712?
CVE-2018-10712 has a high severity rating due to its potential for local privilege escalation.
How do I fix CVE-2018-10712?
To fix CVE-2018-10712, users should update ASRock RGBLED to version 1.0.35.1 or later, A-Tuning to version 3.0.210 or later, F-Stream to version 3.0.210 or later, and RestartToUEFI to version 1.0.6.2 or later.
Which ASRock applications are affected by CVE-2018-10712?
CVE-2018-10712 affects ASRock RGBLED, A-Tuning, F-Stream, and RestartToUEFI applications prior to their respective fixed versions.
What kind of attacks could exploit CVE-2018-10712?
CVE-2018-10712 could be exploited to run arbitrary code with elevated privileges on affected systems.
Is CVE-2018-10712 a remote or local vulnerability?
CVE-2018-10712 is a local vulnerability, requiring local access to the system to exploit.