CVE-2024-30804: Critical severity ASUS Fan Xpert vulnerability
Published Apr 26, 2024
·Updated
An issue discovered in the DeviceIoControl component in ASUS FanXpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.
Affected Software
1 affected component
ASUS Fan Xpert<10013
Event History
Apr 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-30804?
CVE-2024-30804 is considered a critical vulnerability due to its ability to allow arbitrary code execution.
2
How do I fix CVE-2024-30804?
To mitigate CVE-2024-30804, update ASUS Fan Xpert to version 10013 or later.
3
What are the potential impacts of CVE-2024-30804?
Exploiting CVE-2024-30804 could lead to remote code execution, potentially allowing an attacker to gain control of the affected system.
4
What systems are affected by CVE-2024-30804?
CVE-2024-30804 affects ASUS Fan Xpert versions prior to 10013.
5
Can CVE-2024-30804 be exploited remotely?
Yes, CVE-2024-30804 can be exploited remotely through crafted IOCTL requests.