Executive brief
The ASUS System Control Interface, a software component used to manage hardware settings and system functions on ASUS computers, contains a security flaw in how it handles permissions. A local user with limited access can exploit this vulnerability to gain full administrative (SYSTEM) control over the device. This could allow an attacker to install malicious software, access sensitive files, or disrupt the computer's operations.
Technical details
The vulnerability (CWE-732) exists within the ASUS System Control Interface due to incorrect permission assignments for critical resources. A local attacker with low privileges can bypass existing validation mechanisms by sending a specially crafted Remote Procedure Call (RPC) to the affected component. Successful exploitation allows the attacker to escalate privileges to the SYSTEM account and execute arbitrary code. While the attack requires local access, the complexity is rated as high (AC:H) according to the vendor's CVSS 4.0 assessment. Users are advised to refer to the ASUS Security Advisory for available updates.
Affected products
- ASUS System Control Interface
Timeline
- 2026-05-29: disclosed: Initial publication of the CVE record.