CVE-2022-36438
Summary
| CVE | CVE-2022-36438 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-18 12:15:00 UTC |
| Updated | 2023-11-07 03:49:00 UTC |
| Description | AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe before 1.0.10.0. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Asus | Asusswitch | All | All | All | All |
| Application | Asus | System Control Interface | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sign in to your account | MISC | asus-my.sharepoint.com | |
| Sign in to your account | asus-my.sharepoint.com | ||
| ASUS USA | MISC | asus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.