First published: Thu Jul 21 2022(Updated: )
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Aura Ready Game Software Development Kit | =1.0.0.4 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35899 is a vulnerability in the ASUSTeK Aura Ready Game SDK service (GameSDK.exe) version 1.0.0.4, where there is an unquoted service path that may allow a local user to escalate privileges.
CVE-2022-35899 affects the ASUSTeK Aura Ready Game SDK service version 1.0.0.4, allowing a local user to escalate privileges by creating a malicious file.
CVE-2022-35899 has a severity rating of 7.8 (High).
To fix CVE-2022-35899, update to a version of ASUSTeK Aura Ready Game SDK service that does not have the unquoted service path vulnerability (GameSDK.exe version 1.0.0.4), or apply a patch provided by the vendor.
No, Microsoft Windows is not affected by CVE-2022-35899.