Double Free Vulnerability in ASUS System Analysis Service
CVE-2025-2027

5.9MEDIUM

Key Information:

Vendor
Asus
Status
Vendor
CVE Published:
28 March 2025

Summary

A double free vulnerability has been discovered in the ASUS System Analysis service, enabling attackers to exploit specially crafted local RPC requests. This could lead to service crashes and, in rare cases, memory manipulation, posing significant risks to system stability and security. For comprehensive mitigation details, refer to the ASUS Security Advisory.

Affected Version(s)

ASCI before 1.1.32.0

ASCI before 3.1.43.0

ASCI before 3.2.44.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.