AsLdrSrv.exe in ASUS ATK Package before V1.0.0061 (for Windows 10 notebook PCs) could lead to unsigned code execution with no additional execution. The user must put an application at a particular path, with a particular file name.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://safebreach.com/blog | third party advisory |
https://www.asus.com/support/faq/1041545 | vendor advisory |
https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/ | vendor advisory |