CVE-2024-33220
HIGHDescription
An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Is your site exposed to CVE-2024-33220?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| asus | ai_suite |
References
Frequently Asked Questions
What is CVE-2024-33220? +
How severe is CVE-2024-33220? +
What products are affected by CVE-2024-33220? +
How do I check if I'm vulnerable to CVE-2024-33220? +
Related Vulnerabilities
Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative …
ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the …
An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver security mechanisms and …
**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to …
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, …
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via …