CVE-2019-19235 describes a vulnerability in AsLdrSrv.exe within the ASUS ATK Package (versions prior to V1.0.0061 for Windows 10 notebook PCs) that allows for unsigned code execution. An attacker with local access could achieve this by placing a malicious application at a specific path with a particular filename. This vulnerability is rated as HIGH severity (CVSS 7.0) due to its potential for high impact on confidentiality, integrity, and availability, despite requiring high attack complexity and low privileges. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0061CPE matchmatch criteria | cpe:2.3:a:asus:atk_package:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.