---
id: CVE-2022-4989
title: "** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS\_AI Suite 3 driver\_allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.\nRefer t…"
summary: "** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS\_AI Suite 3 driver\_allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.\nRefer t…"
severity: none
cwe:
  - CWE-1284
published: '2026-07-03'
updated: '2026-07-17'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-4989'
references:
  - url: 'https://www.asus.com/security-advisory'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
tags:
  - nvd
epss: 0.00142
epssPercentile: 0.03872
ingestedAt: '2026-07-17T13:12:07.518Z'
---

## Overview

** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.
Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
