PT-2025-47980 · Asus · Asus System Control Interface

Published

2025-11-24

·

Updated

2026-01-02

·

CVE-2025-59373

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
ASUS System Control Interface and Affected Versions ASUS System Control Interface (affected versions not specified)
Description A local privilege escalation issue exists in the restore mechanism of the ASUS System Control Interface. An unprivileged actor can copy files without proper validation into protected system paths, potentially allowing arbitrary files to be executed with SYSTEM privileges. The vulnerability allows a low-privilege local user to escalate to NT AUTHORITYSYSTEM, granting unrestricted control over the machine. No user interaction is required for exploitation. The vulnerability is related to incorrect permission assignment for a critical resource within the AsusSwitchAgent driver of the ASUS System Control Interface (ASCI).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-14692
CVE-2025-59373
ZDI-25-1017

Affected Products

Asus System Control Interface