CVE-2026-8917

8.4

ASUS · GPU Tweak III, GPUTweakII, AI Suite3, VGAdll

An untrusted pointer dereference vulnerability in various ASUS software components allows a local attacker to perform arbitrary memory writes, potentially leading to privilege escalation.

Executive summary

A high severity privilege escalation vulnerability in multiple ASUS utility applications poses a significant risk to local system integrity.

Vulnerability

This is an untrusted pointer dereference vulnerability (CWE-822) occurring within IOCTL handlers. The vulnerability requires high privileges (PR:H) to execute, allowing a local attacker to overwrite arbitrary memory addresses.

Business impact

Successful exploitation of this flaw allows a local user with high privileges to compromise system security, potentially resulting in full system control. With a CVSS score of 8.4, the risk to confidentiality, integrity, and availability is high, necessitating immediate prioritization of mitigation steps on affected workstations and servers.

Remediation

Immediate Action: Review the official ASUS security advisory for the release of patched software versions and apply updates across all systems running the affected utilities.

Proactive Monitoring: Monitor system logs for unusual process execution or unauthorized attempts to interact with kernel-mode drivers associated with ASUS software.

Compensating Controls: Restrict administrative access to systems running these utilities to only authorized personnel to prevent local attackers from reaching the required privilege level for exploitation.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for privilege escalation and the high CVSS score, administrators should treat this vulnerability with urgency. Identify all instances of the affected ASUS software in your environment and prepare to deploy vendor-supplied updates as soon as they become available.

More ASUS CVEs