mirror of
https://github.com/416rehman/asus-bsitf-0-day-poc
synced 2026-08-09 11:55:22 +00:00
Update README with accurate impact assessment and BYOVD definition
This commit is contained in:
@@ -4,7 +4,7 @@
|
||||
|
||||
The ASUS `bsitf.sys` (also distributed as `AsusBSItf.sys`) kernel driver exposes IOCTL `0x222808` which allocates physically contiguous kernel memory of attacker-controlled size, maps it into the calling process's address space with full read/write permissions, and returns both the usermode virtual address and the physical address to the caller.
|
||||
|
||||
The device requires administrator privileges to open. No validation is performed on the allocation size or number of outstanding allocations.
|
||||
The device requires administrator privileges to open, making this an admin-to-kernel escalation. In a BYOVD (Bring Your Own Vulnerable Driver) scenario, an attacker who already has admin (e.g., via social engineering or a separate exploit) can load this legitimately signed driver to gain arbitrary kernel memory access without needing a kernel exploit.
|
||||
|
||||
## Affected Versions
|
||||
|
||||
|
||||
Reference in New Issue
Block a user