SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2019-25764

HIGH · CVSS 7.3 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The ASUS AURA SYNC driver contains an exposed IOCTL with insufficient access control, enabling local users to bypass verification and execute arbitrary IOCTLs, which can lead to privilege escalation. Organizations using affected ASUS hardware should prioritize addressing this vulnerability, especially if they rely on the AURA SYNC driver for system functionality. Given the potential for elevated privileges, it is crucial for system administrators to assess their environments and apply necessary mitigations.

CVE
CVE-2019-25764
Severity
HIGH
CVSS
7.3
EPSS
0.09%

Original NVD Description

**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.