vendor:
Precision TouchPad
by:
Athanasios Tserpelis
9.8
CVSS
CRITICAL
Denial of Service/Privilege Escalation
20
CWE
Product Name: Precision TouchPad
Affected Version From: 11.0.0.25
Affected Version To: 11.0.0.25
Patch Exists: YES
Related CWE: CVE-2019-10709
CPE: a:asus:precision_touchpad
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 RS5 x64
2019
Asus Precision TouchPad 11.0.0.25 – DoS/Privesc
A vulnerability in Asus Precision TouchPad 11.0.0.25 allows an attacker to cause a denial of service or privilege escalation by sending a specially crafted DeviceIoControl request. This vulnerability is due to insufficient input validation when handling DeviceIoControl requests. An attacker can exploit this vulnerability by sending a specially crafted DeviceIoControl request to the vulnerable driver. Successful exploitation of this vulnerability could result in denial of service or privilege escalation.
Mitigation:
Update to the latest version of Asus Precision TouchPad 11.0.0.25.