Stack-based Buffer Overflow in ASUS GPUTweak II Allows for Denial of Service

Stack-based Buffer Overflow in ASUS GPUTweak II Allows for Denial of Service

CVE-2021-28686 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Service via a DeviceIoControl.

Learn more about our User Device Pen Test.