CVE-2018-18536: ASUS Aura Sync Firmware

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

Affected products

  • ASUS Aura Sync Firmware: version 1.07.22 only

Published 2018-12-26. Last modified 2026-06-17.