CVE-2019-25764: ASUS Aura Sync

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Aura Sync: before 1.07.84 (fixed in 1.07.84)

Published 2026-07-17. Last modified 2026-09-29.