CVE-2019-25764
CVE-2019-25764 is a high-severity vulnerability with a CVSS 4.0 base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-782.
Key facts
- Severity: High (CVSS 4.0 base score 7.3)
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-782
- Published:
- Last modified:
Description
**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
Frequently asked questions
- What is CVE-2019-25764?
- **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.
- How severe is CVE-2019-25764?
- CVE-2019-25764 has a CVSS 4.0 base score of 7.3, rated high severity.
- Is CVE-2019-25764 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2019-25764?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2019-25764 published?
- CVE-2019-25764 was published on 2026-07-17.
References
Other CWE-782 vulnerabilities
- CVE-2024-39251 — Critical (CVSS 10.0): An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows…
- CVE-2024-4196 — Critical (CVSS 10.0): An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code…
- CVE-2024-32370 — Critical (CVSS 9.8): An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive…
- CVE-2024-30804 — Critical (CVSS 9.8): An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute…
- CVE-2024-33220 — High (CVSS 8.8): An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate…
- CVE-2021-21789 — High (CVSS 8.8): A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles…