Executive brief
ASUS Business Manager, a software suite used for managing business PCs, contains a security flaw that allows a local user to gain full control over the computer. By sending a specially crafted message to the software, an attacker can execute commands with the highest level of system privileges. This could lead to a total compromise of the device, including unauthorized access to all data and the ability to disable security features.
Technical details
A vulnerability classified as External Control of File Name or Path (CWE-73) exists in ASUS Business Manager versions up to and including v3.0.38.0. The flaw is triggered when the application improperly handles Inter-Process Communication (IPC) messages, allowing a local user with low privileges to manipulate file paths or names. By sending a tampered IPC message, an attacker can achieve arbitrary code execution with SYSTEM-level privileges. ASUS has addressed this in their security advisory, and users are encouraged to update to the latest version of the software.
Affected products
- ASUS ASUS Business Manager v3.0.38.0 and earlier
Timeline
- 2026-07-03: advisory: NVD publication date