An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism.
Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.

Project Subscriptions

Vendors Products
Asus System Control Interface Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 04:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Permission in ASUS System Control Interface

Fri, 29 May 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Asus
Asus asus System Control Interface
Vendors & Products Asus
Asus asus System Control Interface

Fri, 29 May 2026 02:15:00 +0000

Type Values Removed Values Added
Description An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.
Weaknesses CWE-732
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-05-29T16:24:56.103Z

Reserved: 2026-04-30T02:33:01.096Z

Link: CVE-2026-7480

cve-icon Vulnrichment

Updated: 2026-05-29T16:24:49.964Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-29T02:16:17.223

Modified: 2026-05-29T14:46:09.837

Link: CVE-2026-7480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T04:30:27Z

Weaknesses