An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.