CVE-2022-36438

HIGH

AsusSwitch.exe <1.0.10.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe before 1.0.10.0.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 7.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (2)
asus/asusswitch < 1.0.10.0
asus/system_control_interface 3.0.0.0 - 3.1.5.0
Published Oct 18, 2022
Tracked Since Feb 18, 2026