Junglewise Threat Intelligence

CVE-2026-8921: ASUS Business Manager privilege escalation via tampered IPC message

CVE-2026-8921 · Severity: info · CVSS 8.5 · Published 2026-07-03

Technologies: ASUS Business Manager. Vendors: ASUS.

Executive brief

ASUS Business Manager, a software suite used for managing business PCs, contains a security flaw that allows a local user to gain full control over the computer. By sending a specially crafted message to the software, an attacker can execute commands with the highest level of system privileges. This could lead to a total compromise of the device, including unauthorized access to all data and the ability to disable security features.

Technical details

A vulnerability classified as External Control of File Name or Path (CWE-73) exists in ASUS Business Manager versions up to and including v3.0.38.0. The flaw is triggered when the application improperly handles Inter-Process Communication (IPC) messages, allowing a local user with low privileges to manipulate file paths or names. By sending a tampered IPC message, an attacker can achieve arbitrary code execution with SYSTEM-level privileges. ASUS has addressed this in their security advisory, and users are encouraged to update to the latest version of the software.

Affected products

  • ASUS ASUS Business Manager v3.0.38.0 and earlier

Timeline

  • 2026-07-03: advisory: NVD publication date

References

Related threats