{"id":"CVE-2022-4989","title":"** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.\nRefer t…","summary":"** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.\nRefer t…","severity":"none","cwe":["CWE-1284"],"published":"2026-07-03","updated":"2026-07-17","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-4989","references":[{"url":"https://www.asus.com/security-advisory","label":"54bf65a7-a193-42d2-b1ba-8e150d3c35e1"}],"tags":["nvd"],"epss":0.00142,"epssPercentile":0.03855,"ingestedAt":"2026-07-17T13:12:07.518Z","slug":"CVE-2022-4989","body":"## Overview\n\n** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.\nRefer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}