CVE-2022-36439

AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:asus:asusliveupdate:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:asussoftwaremanger:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:system_control_interface:*:*:*:*:*:*:*:*

History

13 May 2025, 15:15

Type Values Removed Values Added
CWE CWE-276

Information

Published : 2022-10-18 12:15

Updated : 2025-05-13 15:15


NVD link : CVE-2022-36439

Mitre link : CVE-2022-36439

CVE.ORG link : CVE-2022-36439


JSON object : View

Products Affected

asus

  • asussoftwaremanger
  • system_control_interface
  • asusliveupdate
CWE
NVD-CWE-noinfo CWE-276

Incorrect Default Permissions