Vulnerability Description
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asus | Asusliveupdate | < 1.0.45.0 |
| Asus | Asussoftwaremanger | < 1.0.53.0 |
| Asus | System Control Interface | >= 3.0.0.0, < 3.1.5.0 |
Related Weaknesses (CWE)
References
- https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedriv
- https://asus.comVendor Advisory
- https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedriv
- https://asus.comVendor Advisory
FAQ
What is CVE-2022-36439?
CVE-2022-36439 is a vulnerability with a CVSS score of 6.0 (MEDIUM). AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via S...
How severe is CVE-2022-36439?
CVE-2022-36439 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36439?
Check the references section above for vendor advisories and patch information. Affected products include: Asus Asusliveupdate, Asus Asussoftwaremanger, Asus System Control Interface.