Asus Aura Sync Multiple Arbitrary Code Execution Vulnerabilities
BID:106250
CVE-2018-18535 | CVE-2018-18536 | CVE-2018-18537 |Info
Asus Aura Sync Multiple Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 106250 |
| Class: | Access Validation Error |
| CVE: |
CVE-2018-18535 CVE-2018-18536 CVE-2018-18537 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 18 2018 12:00AM |
| Updated: | Dec 18 2018 12:00AM |
| Credit: | Diego Juarez |
| Vulnerable: |
Asus Aura Sync 1.7.22 |
| Not Vulnerable: | |
Discussion
Asus Aura Sync Multiple Arbitrary Code Execution Vulnerabilities
Asus Aura Sync is prone to multiple arbitrary code-execution vulnerabilities.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the affected application and gain elevated privileges. Failed exploits will result in denial-of-service conditions.
ASUS Aura Sync 1.07.22 is vulnerable; other versions may also be affected.
Asus Aura Sync is prone to multiple arbitrary code-execution vulnerabilities.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the affected application and gain elevated privileges. Failed exploits will result in denial-of-service conditions.
ASUS Aura Sync 1.07.22 is vulnerable; other versions may also be affected.