Arbitrary Read and Write Vulnerability in ASUS System Analysis IO Component
CVE-2024-55408

5.1MEDIUM

Key Information:

Vendor
Asus
Status
Vendor
CVE Published:
6 January 2025

Summary

The AsusSAIO.sys component in ASUS System Analysis IO version 1.0.0 is susceptible to arbitrary read and write operations, which can be exploited by attackers. This vulnerability arises from inadequately secured IOCTL requests, allowing malicious actors to craft requests that can manipulate memory and I/O operations, potentially leading to unauthorized data access or system modifications. It underscores the importance of proper input validation and access controls in driver design. For further details, visit ASUS or view the GitHub reference.

Affected Version(s)

ASCI before 1.0.30.0

ASCI before 1.0.30.0

ASCI before 3.1.41.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.