Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-36439


AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0.


Published

2022-10-18T12:15:09.473

Last Modified

2025-05-13T15:15:49.003

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.0 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application asus asusliveupdate < 1.0.45.0 Yes
Application asus asussoftwaremanger < 1.0.53.0 Yes
Application asus system_control_interface < 3.1.5.0 Yes

References