CVE-2018-18536 describes a high-severity vulnerability in the GLCKIo and Asusgio low-level drivers within ASUS Aura Sync v1.07.22 and earlier, allowing attackers to read/write data from/to IO ports. This local vulnerability, with low attack complexity, can lead to arbitrary code execution with elevated privileges, resulting in high impacts to confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has received some community discussion and media coverage, though it is not currently on the CISA KEV catalog or considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.07.22CPE matchmatch criteria | cpe:2.3:o:asus:aura_sync_firmware:1.07.22:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.