PT-2025-47980 · Asus · Asus System Control Interface
Published
2025-11-24
·
Updated
2026-01-02
·
CVE-2025-59373
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
ASUS System Control Interface and Affected Versions
ASUS System Control Interface (affected versions not specified)
Description
A local privilege escalation issue exists in the restore mechanism of the ASUS System Control Interface. An unprivileged actor can copy files without proper validation into protected system paths, potentially allowing arbitrary files to be executed with SYSTEM privileges. The vulnerability allows a low-privilege local user to escalate to
NT AUTHORITYSYSTEM, granting unrestricted control over the machine. No user interaction is required for exploitation. The vulnerability is related to incorrect permission assignment for a critical resource within the AsusSwitchAgent driver of the ASUS System Control Interface (ASCI).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus System Control Interface