Executive brief
ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and VGA DLL contain an IOCTL vulnerability that allows a local attacker to write arbitrary values to memory, potentially escalating privileges on the system. This affects system utility software used to manage GPU settings and performance, putting the integrity and security of the entire device at risk.
Technical details
An untrusted pointer dereference vulnerability exists in the IOCTL handlers of ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and VGAdll. The vulnerability allows a local, authenticated attacker to supply a malicious pointer via IOCTL, which the driver dereferences without validation, enabling arbitrary memory writes. This can be exploited to overwrite critical kernel structures, bypass security mechanisms, or achieve privilege escalation from user-mode to kernel-mode execution. The attack requires local access but does not require elevated privileges as a precondition. Patches and security updates are available from ASUS.
Affected products
- ASUS GPU Tweak III <UNKNOWN>
- ASUS GPU Tweak II <UNKNOWN>
- ASUS AI Suite 3 <UNKNOWN>
- ASUS VGAdll <UNKNOWN>
Timeline
- 2026-08-11: disclosed