DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://www.asus.com/Static_WebPage/ASUS-Product-Security-Advisory/ | vendor advisory |
https://www.asus.com/support/FAQ/1042640/ | vendor advisory |
https://drive.google.com/file/d/1Ap293b7bZLen6DmheppR1IUFEAsCSORC/view?usp=sharing | mailing list exploit third party advisory |
https://www.asus.com/Laptops/ASUS-TUF-Gaming-FX504/HelpDesk_Download/ | vendor advisory |