CVE-2019-10709

CRITICAL

Asus Precision TouchPad 11.0.0.25 - Denial of Service or Privilege Escalation via Crafted DeviceIoControl Call

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-10709. PoCs published by Athanasios Tserpelis.

AI-analyzed exploit summary This exploit targets a vulnerability in Asus Precision TouchPad driver (11.0.0.25) by sending a malformed buffer via DeviceIoControl to trigger a denial-of-service or potential privilege escalation. The PoC demonstrates a buffer overflow via a crafted input to the driver.

Description

AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.

Exploits (1)

exploitdb WORKING POC
by Athanasios Tserpelis · pythondoswindows
https://www.exploit-db.com/exploits/47322

This exploit targets a vulnerability in Asus Precision TouchPad driver (11.0.0.25) by sending a malformed buffer via DeviceIoControl to trigger a denial-of-service or potential privilege escalation. The PoC demonstrates a buffer overflow via a crafted input to the driver.

Classification
Working Poc 90%
Attack Type
Dos | Lpe
Complexity
Trivial
Reliability
Reliable
Target: Asus Precision TouchPad 11.0.0.25
No auth needed
Prerequisites: Windows 10 RS5 x64 · Asus Precision TouchPad driver 11.0.0.25 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.1154
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
asus/precision_touchpad 11.0.0.25
Published Sep 04, 2019
Tracked Since Feb 18, 2026