Executive brief
A vulnerability in the ASUS AURA SYNC driver, which manages RGB lighting on ASUS hardware, could allow a local user to gain elevated system privileges. By bypassing security checks within the driver, an attacker with limited access to a computer could take full control of the operating system. This issue affects legacy versions of the software that are no longer supported by the manufacturer.
Technical details
The ASUS AURA SYNC driver contains an 'Exposed IOCTL with Insufficient Access Control' vulnerability (CWE-782). The root cause is a failure in the driver's verification mechanism, which allows a local attacker with low privileges to invoke arbitrary Input/Output Control (IOCTL) codes. By sending specially crafted requests to the driver, an attacker can execute code with kernel-level privileges, leading to a full system compromise. This vulnerability affects AURA SYNC versions prior to 1.07.84. ASUS has designated this as 'Unsupported When Assigned,' indicating it affects legacy drivers that have reached end-of-life.
Affected products
- ASUS AURA SYNC before 1.07.84
Timeline
- 2026-07-17: advisory: NVD and ASUS published the vulnerability details.