An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Link | Tags |
---|---|
https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33220 | third party advisory exploit |