CVE-2018-18537: ASUS Aura Sync Firmware

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.

Affected products

  • ASUS Aura Sync Firmware: version 1.07.22 only

Published 2018-12-26. Last modified 2026-06-17.