CVE-2022-36439

MEDIUM

ASUS System Control Interface <3.1.5.0 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0.

Scores

CVSS v3 6.0
EPSS 0.0004
EPSS Percentile 11.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (3)
asus/asusliveupdate < 1.0.45.0
asus/asussoftwaremanger < 1.0.53.0
asus/system_control_interface 3.0.0.0 - 3.1.5.0
Published Oct 18, 2022
Tracked Since Feb 18, 2026