Junglewise Threat Intelligence

CVE-2022-4989: ASUS AI Suite 3 privilege escalation in driver

CVE-2022-4989 · Severity: info · CVSS 8.5 · Published 2026-07-03

Technologies: ASUS AI Suite 3. Vendors: ASUS.

Executive brief

A vulnerability in the ASUS AI Suite 3 driver, a utility used for managing motherboard settings and system performance, could allow a local user to gain elevated system privileges. By sending specially crafted requests to the driver, an attacker can access restricted memory areas, potentially leading to full control over the affected computer. This could result in unauthorized data access or the installation of malicious software.

Technical details

An improper validation of specified quantity in input vulnerability (CWE-1284) exists in the ASUS AI Suite 3 driver. The flaw is triggered when the driver processes specially crafted Input/Output Control (IOCTL) requests from a local user. Due to insufficient validation of input parameters, the driver may access unintended memory regions. A local attacker with low privileges can exploit this to achieve kernel-level execution or privilege escalation. The vulnerability is addressed in AI Suite 3 version v3.03.00 or later.

Affected products

  • ASUS AI Suite 3 before v3.03.00

Timeline

  • 2022: disclosed: CVE year designation
  • 2026-07-03: advisory: NVD publication date

References

Related threats