nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25764 CVE-2019-25764
HIGH
ASUS AURA SYNC Exposed IOCTL with Insufficient Access Control
Record summary
CVE-2019-25764 has a selected CVSS score of 7.3 (high).
Description
**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AURA SYNCBrowse ASUS / AURA SYNCDefault status: unaffected | CVE List | Before 1.07.84 | affected |
References
2asus.com
https://www.asus.com/security-advisory