Security Advisory

CVE-2019-25764

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-17 06:00:10
Last updated 2026-07-17 10:10:36
Assigner ASUS
CVSS score 7.3
State PUBLISHED

Description

**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.