CVE-2019-17603 is a local privilege escalation and denial-of-service vulnerability affecting Asus Aura Sync versions through 1.07.71. The Ene.sys driver fails to properly validate input for specific IOCTLs, allowing a local attacker to trigger memory corruption with crafted kernel addresses. This can lead to a system crash or arbitrary code execution with elevated privileges. While rated High severity (CVSS 7.8), there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.07.71CPE matchmatch criteria | cpe:2.3:a:asus:aura_sync:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.