CVE-2022-44898EPSS p28.7%
CVE-2022-44898CVE-2022-44898
asus / aura_sync
Description
The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted IOCTL requests.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.37% probability of exploitation · percentile 28.7% · 2026-06-19T12:03:05Z |
| Last modified | 2026-06-17 |