First published: Mon Sep 27 2021(Updated: )
ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Armoury Crate Lite Service | <4.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this ASUS ROG Armoury Crate Lite vulnerability is CVE-2021-40981.
The severity of CVE-2021-40981 vulnerability is high with a severity value of 7.3.
Local users can gain privileges in ASUS ROG Armoury Crate Lite before version 4.2.10 by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.
The affected software by CVE-2021-40981 vulnerability is Asus Armoury Crate Lite Service version up to 4.2.10.
Yes, there is a reference available for CVE-2021-40981 vulnerability. You can find it at https://aptw.tf/2021/09/24/armoury-crate-privesc.html.