CVE-2022-44898

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
14/12/2022
Last modified:
22/04/2025

Description

The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asus:aura_sync:*:*:*:*:*:*:*:* 1.07.79 (including)