CVE-2024-33221: ASUS BIOS Flash Driver

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

Affected products

  • ASUS BIOS Flash Driver: version 3.2.12.0 only

Published 2024-05-22. Last modified 2026-06-17.