CVE-2019-17603

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
02/06/2020
Last modified:
25/06/2020

Description

Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asus:aura_sync:*:*:*:*:*:*:*:* 1.07.71 (including)