ASUS Armoury Crate Service - Arbitrary File Creation via Elevation of Privilege Flaw
Vulnerability Description
Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-38699
Credits & Attribution
No credits recorded in the NVD database.
More from ASUS
View All →Affected Vendor
ASUS
View all reports →