VulnerabilityModified
CVE-2021-28686
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow.
MEDIUM 5.5EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Service via a DeviceIoControl.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- asus/gputweak ii
- Source
- cve@mitre.org
References
- https://gist.github.com/DStraghkov/fba4994ac4bb3a6e2940b21743563df0Third Party Advisory
- https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/Vendor Advisory
- https://gist.github.com/DStraghkov/fba4994ac4bb3a6e2940b21743563df0Third Party Advisory
- https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.