---
id: CVE-2019-25764
title: "**UNSUPPORTED WHEN ASSIGNED**\_ Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.\n\nRefer to …"
summary: "**UNSUPPORTED WHEN ASSIGNED**\_ Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.\n\nRefer to …"
severity: none
cwe:
  - CWE-782
published: '2026-07-17'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T09:10:00.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25764'
references:
  - url: 'https://www.asus.com/security-advisory'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
tags:
  - nvd
epss: 0.00122
epssPercentile: 0.01748
ingestedAt: '2026-09-29T09:30:49.079Z'
---

## Overview

**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.

Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
