Vulnerability record · CVE-2008-1491 · published 25 March 2008
CVE-2008-1491: ASUS Remote Console DPC Proxy stack buffer overflow
Asus · Remote Console
The DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (ARC/ASMB3) 2.0.0.19 and 2.0.0.24 contains a stack-based buffer overflow reachable over TCP port 623. A remote attacker sending a long string can overwrite stack memory and execute arbitrary code. The flaw is severe because it is network-reachable, needs no authentication, and affects a management service.
Description
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code via a long string to TCP port 623.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS base score of 10 and high EPSS probability, though the product is old and likely limited in deployment.
What it is
The DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (ARC/ASMB3) 2.0.0.19 and 2.0.0.24 contains a stack-based buffer overflow reachable over TCP port 623. A remote attacker sending a long string can overwrite stack memory and execute arbitrary code. The flaw is severe because it is network-reachable, needs no authentication, and affects a management service.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the DpcProxy service, potentially taking full control of the host.
Attack surface
Reachable over the network via TCP port 623; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.70132 (99.3rd percentile) and public exploit references exist, including an Exploit-tagged advisory and an Exploit-DB entry, so exploitation is feasible and likely.
What to do
- Apply the vendor fix or upgrade ASUS Remote Console/ASMB3 to a version later than 2.0.0.24; if no patch is available, treat the service as unsupported.
- Block or restrict TCP port 623 to trusted management networks only.
- Disable the DPC Proxy service if it is not required.
- Segment management interfaces from general user and internet-facing networks.
- Monitor for vendor advisories and replace end-of-life ASUS Remote Console deployments.
Detection
- Alert on inbound connections to TCP port 623 from untrusted sources.
- Monitor DpcProxy.exe for crashes or abnormal process termination.
- Inspect network traffic to port 623 for oversized or malformed payloads.
- Watch for unexpected child processes or code execution spawned by DpcProxy.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1491 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1491), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.