Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-36438


AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe before 1.0.10.0.


Published

2022-10-18T12:15:09.420

Last Modified

2025-05-13T15:15:48.827

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-276
  • Type: Secondary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application asus asusswitch < 1.0.10.0 Yes
Application asus system_control_interface < 3.1.5.0 Yes

References