7.2
CVSSv2

CVE-2019-17603

Published: 02/06/2020 Updated: 25/06/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Ene.sys in Asus Aura Sync up to and including 1.07.71 does not properly validate input to IOCTL 0x80102044, 0x80102050, and 0x80102054, which allows local users to cause a denial of service (system crash) or gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

asus aura sync

Exploits

ASUS Aura Sync version 10771 enesys privilege escalation kernel exploit ...

Github Repositories

Some personal exploits/pocs

Exploits Miscellaneous proof of concept exploit code for testing purposes Current Exploits Fortinet FortiOS 600 <= 604, 560 <= 568, 541 <= 5410: The magic backdoor (CVE-2018-13382) Strato HiDrive <= 5010 LPE (CVE-2019-9486) Exim 487 < 491 LPE (CVE-2019-10149) ASUS Aura Sync <= 10771 Stack-Based Buffer Overflow (CVE-