CVE-2022-36439
MEDIUMASUS System Control Interface <3.1.5.0 - Local Privilege Escalation
Title source: llmDescription
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0.
References (2)
Core 2
Core References
Vendor Advisory
https://asus.com
Scores
CVSS v3
6.0
EPSS
0.0004
EPSS Percentile
11.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-276
Status
published
Products (3)
asus/asusliveupdate
< 1.0.45.0
asus/asussoftwaremanger
< 1.0.53.0
asus/system_control_interface
3.0.0.0 - 3.1.5.0
Published
Oct 18, 2022
Tracked Since
Feb 18, 2026