Local Privilege Escalation in ASUS GPUTweak II Drivers
CVE-2021-28685
7.8HIGH
What is CVE-2021-28685?
The ASUS GPUTweak II drivers, specifically AsIO2_64.sys and AsIO2_32.sys, prior to version 2.3.0.3, contain a vulnerability that allows low-privileged users to access physical memory directly. This flaw facilitates the mapping of physical memory into the virtual address space of a process and the interaction with Model Specific Register (MSR) registers. Exploiting this vulnerability could allow an attacker to elevate their privileges to NT AUTHORITY\SYSTEM, thereby gaining control over the system.