CVE-2020-10649: ASUS Device Activation

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.

Affected products

  • ASUS Device Activation: before 1.0.7.0 (fixed in 1.0.7.0)

Published 2020-03-25. Last modified 2026-06-17.