A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation.
For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory/ |
|
History
Thu, 06 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Asus
Asus armoury Crate |
|
| Vendors & Products |
Asus
Asus armoury Crate |
Thu, 06 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Nov 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory. | |
| Weaknesses | CWE-119 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published: 2025-11-06T06:02:48.738Z
Updated: 2025-11-06T15:37:38.417Z
Reserved: 2025-08-22T05:27:02.208Z
Link: CVE-2025-9338
Updated: 2025-11-06T15:37:35.326Z
Status : Awaiting Analysis
Published: 2025-11-06T06:15:44.533
Modified: 2025-11-06T19:45:09.883
Link: CVE-2025-9338
No data.