VulnerabilityModified
CVE-2019-19235
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution.
HIGH 7.0EPSS 0.38%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. The user must put an application at a particular path, with a particular file name.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- asus/atk package
- Source
- cve@mitre.org
References
- https://safebreach.com/blogThird Party Advisory
- https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/Vendor Advisory
- https://www.asus.com/support/faq/1041545Vendor Advisory
- https://safebreach.com/blogThird Party Advisory
- https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/Vendor Advisory
- https://www.asus.com/support/faq/1041545Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.