CVE-2018-18537 describes a vulnerability in the ASUS Aura Sync v1.07.22 and earlier low-level driver (GLCKIo) that allows an attacker to write an arbitrary DWORD to an arbitrary memory address. This local privilege escalation vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring local user privileges, with a high impact on integrity but no impact on confidentiality or availability. While there is no known active exploitation (KEV list) or public exploit code (Metasploit, ExploitDB), the vulnerability has received some community discussion and media coverage, including a BleepingComputer article detailing proof-of-concept availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.07.22CPE matchmatch criteria | cpe:2.3:o:asus:aura_sync_firmware:1.07.22:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.