CVE-2024-30804

CRITICAL

ASUS Fan_Xpert < 10013 - Remote Code Execution via Crafted IOCTL Requests

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-30804. PoCs published by ekfkawl.

AI-analyzed exploit summary This repository contains a functional local privilege escalation (LPE) exploit for CVE-2024-30804, targeting the ASUS AsInsHelp64.sys driver. The exploit abuses arbitrary physical memory read/write capabilities to overwrite kernel tokens and escalate privileges to SYSTEM.

Description

An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

Exploits (1)

nomisec WORKING POC 4 stars
by ekfkawl · poc
https://github.com/ekfkawl/CVE-2024-30804

This repository contains a functional local privilege escalation (LPE) exploit for CVE-2024-30804, targeting the ASUS AsInsHelp64.sys driver. The exploit abuses arbitrary physical memory read/write capabilities to overwrite kernel tokens and escalate privileges to SYSTEM.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: ASUS AsInsHelp64.sys (related to ASUS Fan Xpert < v.10013)
No auth needed
Prerequisites: ASUS AsInsHelp64.sys driver loaded · Windows 10 (2004) to Windows 11 (23H2) x64 · WinDbg for manual address retrieval
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0082
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-782
Status published
Published Apr 26, 2024
Tracked Since Feb 18, 2026