Junglewise Threat Intelligence

CVE-2022-4990: ASUS AI Suite 3 privilege escalation in driver

CVE-2022-4990 · Severity: info · CVSS 7.3 · Published 2026-07-03

Technologies: ASUS AI Suite 3. Vendors: ASUS.

Executive brief

ASUS AI Suite 3 is a performance tuning and system monitoring utility for ASUS motherboards. A security flaw in its system driver allows a local user with low privileges to access restricted memory areas. This could allow an attacker to gain full administrative control over the computer, potentially leading to data theft or persistent system compromise.

Technical details

A vulnerability exists in the ASUS AI Suite 3 driver due to improper validation of specified quantities in input (CWE-1284). A local attacker with low privileges can issue specially crafted I/O Control (IOCTL) requests to the driver to bypass security validations. This allows the attacker to access restricted memory blocks, which can be leveraged to achieve kernel-level privilege escalation. The issue is addressed in versions v3.03.00 and later.

Affected products

  • ASUS AI Suite 3 before v3.03.00

Timeline

  • 2026-07-03: advisory: NVD publication date
  • 2026-07-02: disclosed: ASUS reported the vulnerability to CVE list

References

Related threats