10-23-2018 09:11 PM
12-23-2018 12:56 PM
SaLSouL wrote:
Source of the report https://www.guru3d.com/news-story/asus-aura-sync-and-gigabyte-xtreme-software-contain-vulnerabilitie...
Details:
A security company called SecureAuth shares word that that two drivers from Asus and also two from Gigabyte contain vulnerabilities. The drivers come bundled with tools that companies provide for motherboards and video cards.In total, there are seven vulnerabilities affecting five software products, and researchers wrote exploit code for each of them. Many of them might still be unaddressed. Two of the vulnerable drivers are installed by the Aura Sync software (v1.07.22 and earlier) from ASUS and the flaws they carry can be exploited for local code execution reports tweakers.net via bleeping computer:The vulnerabilities lead to privilege escalation via software like the GIGABYTE App Center (v1.05.21 and below), AORUS Graphics Engine (v1.33 and below), the XTREME Engine utility (v1.25 and earlier), and OC Guru II (v2.08). The vulnerabilities are tagged under CVE-2018-18535, CVE-2018-18536 and CVE-2018-1853. The first and last allow the execution of code with elevated rights, the second can lead to the reading and writing of data via the I/O ports.ASUS has been informed in November last year. In April, Asus released a new version of Aura Sync, but it only fixed two of the three problems, according to SecureAuth.Vulnerable PackagesASUS Aura Sync v1.07.22 and previous versions
What does Asus recommend we do @raja @MasterC
-regards
Sal
12-24-2018 02:53 AM
Abaidor wrote:
This is important and needs to be addressed..Please Asus respond!
Impact : Code execution
Remotely Exploitable : No
Locally Exploitable : Yes
12-24-2018 09:14 AM
MoKiChU wrote:
Concretely, if no one physically accesses your PC, you do not risk anything at all :
https://www.secureauth.com/labs/advisories/asus-drivers-elevation-privilege-vulnerabilities
12-26-2018 01:45 AM
SaLSouL wrote:
Source of the report https://www.guru3d.com/news-story/asus-aura-sync-and-gigabyte-xtreme-software-contain-vulnerabilitie...
Details:
A security company called SecureAuth shares word that that two drivers from Asus and also two from Gigabyte contain vulnerabilities. The drivers come bundled with tools that companies provide for motherboards and video cards.In total, there are seven vulnerabilities affecting five software products, and researchers wrote exploit code for each of them. Many of them might still be unaddressed. Two of the vulnerable drivers are installed by the Aura Sync software (v1.07.22 and earlier) from ASUS and the flaws they carry can be exploited for local code execution reports tweakers.net via bleeping computer:The vulnerabilities lead to privilege escalation via software like the GIGABYTE App Center (v1.05.21 and below), AORUS Graphics Engine (v1.33 and below), the XTREME Engine utility (v1.25 and earlier), and OC Guru II (v2.08). The vulnerabilities are tagged under CVE-2018-18535, CVE-2018-18536 and CVE-2018-1853. The first and last allow the execution of code with elevated rights, the second can lead to the reading and writing of data via the I/O ports.ASUS has been informed in November last year. In April, Asus released a new version of Aura Sync, but it only fixed two of the three problems, according to SecureAuth.Vulnerable PackagesASUS Aura Sync v1.07.22 and previous versions
What does Asus recommend we do @raja @MasterC
-regards
Sal
12-21-2018 07:28 AM
12-22-2018 01:50 AM
12-26-2018 06:42 AM
12-26-2018 08:14 AM
12-26-2018 11:31 PM