{"id":"CVE-2025-9338","title":"A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver","summary":"A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalatio…","severity":"none","cwe":["CWE-119"],"published":"2025-11-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-9338","references":[{"url":"https://www.asus.com/security-advisory/","label":"54bf65a7-a193-42d2-b1ba-8e150d3c35e1"}],"tags":["nvd"],"epss":0.00133,"epssPercentile":0.02403,"ingestedAt":"2026-10-07T21:54:14.926Z","slug":"CVE-2025-9338","body":"## Overview\n\nA improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation.\nFor additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}