CVE-2018-18535: ASUS Aura Sync Firmware
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
Affected products
- ASUS Aura Sync Firmware: version 1.07.22 only
Published 2018-12-26. Last modified 2026-06-17.