CVE-2025-2027 – ASUS System Analysis Double Free Vulnerability

The following table lists the changes that have been made to the
CVE-2025-2027 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 54bf65a7-a193-42d2-b1ba-8e150d3c35e1

    Mar. 28, 2025

    Action Type Old Value New Value
    Added Description A double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered by sending specially crafted local RPC requests, leading to the service crash and potentially memory manipulation in some rare circumstances.
    Refer to the ‘Security Update for MyASUS’ section on the ASUS Security Advisory for more information.
    Added CVSS V4.0 AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-415
    Added Reference https://www.asus.com/content/asus-product-security-advisory/
Share the Post:

Related Posts