CVE-2018-18537

MEDIUM IN THE WILD

ASUS Aura Sync <1.07.22 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-18537 has been observed exploited in the wild (reported by InTheWild.io).

Description

The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106250
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/150893/ASUS-Driver-Privilege-Escalation.html
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Dec/34

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 25.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

InTheWild.io 2022-02-01
Status published
Products (1)
asus/aura_sync_firmware 1.07.22
Published Dec 26, 2018
Tracked Since Feb 18, 2026