CVE-2018-18536

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/12/2018
Last modified:
24/08/2020

Description

The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:aura_sync_firmware:1.07.22:*:*:*:*:*:*:*
cpe:2.3:h:asus:aura_sync:-:*:*:*:*:*:*:*