CVE-2025-9338 Details
Description
A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.
A buffer overflow vulnerability has been identified in the AsIO3.sys driver, allowing for improper restriction of operations within memory bounds. This issue can be exploited by manually executing a specially crafted process, potentially leading to local privilege escalation. The vulnerability affects versions of the Armoury Crate App prior to 6.3.4.
Users can update to the latest version of the Armoury Crate App to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 6, 2025CISA-ADP
Assessed Nov 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asus.com/security-advisory/ | ASUS | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | ASUS |
Affected Products
| Product | Versions |
|---|---|
| ASUS Armoury Crate App | < V6.3.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ASUS |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 6, 2025 | New CVE Received | ASUS |
Volerion