Vulnerability Description
Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asus | Aura Sync | <= 1.07.71 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/158221/ASUS-Aura-Sync-1.07.71-Privilege-Esc
- https://zer0-day.pw/2020-06/asus-aura-sync-stack-based-buffer-overflow/ExploitThird Party Advisory
- http://packetstormsecurity.com/files/158221/ASUS-Aura-Sync-1.07.71-Privilege-Esc
- https://zer0-day.pw/2020-06/asus-aura-sync-stack-based-buffer-overflow/ExploitThird Party Advisory
FAQ
What is CVE-2019-17603?
CVE-2019-17603 is a vulnerability with a CVSS score of 7.8 (HIGH). Ene.sys in Asus Aura Sync through 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain...
How severe is CVE-2019-17603?
CVE-2019-17603 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17603?
Check the references section above for vendor advisories and patch information. Affected products include: Asus Aura Sync.