First published: Wed Mar 25 2020(Updated: )
DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ASUS Device Activation | <1.0.7.0 | |
Microsoft Windows 10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10649 is classified as a high severity vulnerability due to the potential for unsigned code execution.
To mitigate CVE-2020-10649, update ASUS Device Activation to version 1.0.7.0 or later.
CVE-2020-10649 affects ASUS Device Activation software on Windows 10 notebooks and PCs.
CVE-2020-10649 is associated with unsigned code execution vulnerabilities.
While there is no public information on an active exploit for CVE-2020-10649, the vulnerability itself allows for significant risk if exploited.