First published: Thu Apr 08 2021(Updated: )
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual address space of the calling process) and to interact with MSR registers. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ASUS GPUTweak II | <2.3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28685 is a vulnerability in ASUS GPUTweak II before 2.3.0.3 that allows low-privileged users to interact directly with physical memory and MSR registers.
CVE-2021-28685 allows low-privileged users to interact directly with physical memory and MSR registers in ASUS GPUTweak II before version 2.3.0.3.
CVE-2021-28685 has a severity rating of 7.8 (high).
ASUS GPUTweak II versions before 2.3.0.3 are affected by CVE-2021-28685.
To fix CVE-2021-28685, update ASUS GPUTweak II to version 2.3.0.3 or higher.