Advantech SUSI Driver Improper Access Control Vulnerability Allowing Privilege Escalation and Arbitrary Code Execution

Vulnerability

A vulnerability in the Advantech SUSI driver (susi.sys) related to improper access control has been identified. This vulnerability allows attackers to read and write arbitrary memory, I/O ports, and Model Specific Registers (MSRs). The consequences of this vulnerability include privilege escalation, arbitrary code execution, and unauthorized information disclosure. It affects Advantech SUSI versions 5.0.24335 and prior.

Impact

Exploitation of this vulnerability could lead to unauthorized access to privileged resources, allowing for elevated rights and the execution of arbitrary code within the affected system.

Remediation

Users can upgrade to Advantech SUSI version 5.0.24336 to address this vulnerability.

Added: Dec 16, 2025, 6:16 AM
Updated: Dec 16, 2025, 3:14 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.