CVE-2023-26911: High severity ASUS Armoury Crate vulnerability
Published Jul 26, 2023
·Updated
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
Affected Software
2 affected components
ASUS Armoury Crate<=5.3.4.0
ASUS SetupAsusServices<=1.0.5.1
Event History
Jul 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-26911.
2
What is the title of this vulnerability?
The title of this vulnerability is ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability.
3
What is the severity of CVE-2023-26911?
The severity of CVE-2023-26911 is high, with a severity score of 7.8.
4
Which software versions are affected by CVE-2023-26911?
ASUS Armoury Crate version 5.3.4.0 and ASUS SetupAsusServices version 1.0.5.1 are affected by CVE-2023-26911.
5
How can local users exploit this vulnerability?
This vulnerability allows local users to launch processes with elevated privileges.