CVE-2025-2027
Severity CVSS v4.0:
MEDIUM
Type:
CWE-415
Double Free
Publication date:
28/03/2025
Last modified:
28/03/2025
Description
A double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered by sending specially crafted local RPC requests, leading to the service crash and potentially memory manipulation in some rare circumstances.<br />
Refer to the &#39;Security Update for MyASUS&#39; section on the ASUS Security Advisory for more information.
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM