github.com
https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33221 CVE-2024-33221
HIGH
Record summary
CVE-2024-33221 has a selected CVSS score of 7.8 (high).
Description
An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
bios_flash_driverBrowse asus / bios_flash_driverDefault status: unknown | CVE List | 3.2.12.0 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33221