cbcvebase.
CVE-2022-36439
published 2022-10-18

CVE-2022-36439: AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and…

PriorityP426medium6CVSS 3.1
AVLACLPRHUINSUCNIHAH
EPSS
0.16%
5.9th percentile
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0.

Affected

3 ranges
VendorProductVersion rangeFixed in
asusasusliveupdate< 1.0.45.01.0.45.0
asusasussoftwaremanger< 1.0.53.01.0.53.0
asussystem_control_interface>= 3.0.0.0 < 3.1.5.03.1.5.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.