First published: Wed Dec 26 2018(Updated: )
The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Aura Sync Firmware | =1.07.22 | |
Asus Aura Sync |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-18536.
The affected software is Asus Aura Sync v1.07.22 and earlier.
The severity of CVE-2018-18536 is high with a CVSS score of 7.8.
This vulnerability can be exploited by reading and writing data from/to IO ports, which can lead to running code with elevated privileges.
Yes, you can find references for CVE-2018-18536 at the following URLs: [URL1], [URL2], [URL3].