Stack-Based Buffer Overflow in ASUS GPUTweak II Driver
CVE-2021-28686
5.5MEDIUM
Summary
The ASUS GPUTweak II drivers, AsIO2_64.sys and AsIO2_32.sys, prior to version 2.3.0.3, are susceptible to a stack-based buffer overflow. This vulnerability allows low-privileged users to exploit the device's security model, potentially causing a Denial of Service through specially crafted requests sent to DeviceIoControl. Immediate attention to software updates is recommended to mitigate this vulnerability.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved