CVE Feed

    Dashboard / CVE / CVE-2022-44898

    CVE-2022-44898

    The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.

    Published:Dec 14, 2022
    Last Modified:Apr 22, 2025
    EPS:Dec 14, 2022
    EPSS Score:0.00055
    CVSS Score:7.8

    Affected Products

    Vendor
    Asus
    Product
    Aura Sync

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High