CVE-2024-33221: ASUS BIOS Flash Driver
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Affected products
- ASUS BIOS Flash Driver: version 3.2.12.0 only
Published 2024-05-22. Last modified 2026-06-17.