PT-2026-44742 · Asus · Asus System Control Interface

CVE-2026-7480

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v4.0

7.3

High

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ASUS System Control Interface (affected versions not specified)
Description An incorrect permission assignment for critical resources in the ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code. This is achieved through a crafted RPC (Remote Procedure Call) call that bypasses the validation mechanism.

Fix

LPE

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7480
ZDI-26-328

Affected Products

Asus System Control Interface