Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2gm-8gg9-5mh6

Опубликовано: 25 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

A local privilege escalation vulnerability exists in

the restore mechanism of

ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please refer to section Security Update for MyAsus in the ASUS Security Advisory.

A local privilege escalation vulnerability exists in

the restore mechanism of

ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please refer to section Security Update for MyAsus in the ASUS Security Advisory.

EPSS

Процентиль: 4%
0.00019
Низкий

8.5 High

CVSS4

Дефекты

CWE-732

Связанные уязвимости

nvd
3 месяца назад

A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please refer to section Security Update for MyAsus in the ASUS Security Advisory.

CVSS3: 7.8
fstec
3 месяца назад

Уязвимость компонента AsusSwitchAgent драйвера ASUS System Control Interface (ASCI), позволяющая нарушителю выполнить произвольный код с правами system

EPSS

Процентиль: 4%
0.00019
Низкий

8.5 High

CVSS4

Дефекты

CWE-732