CVE-2026-7480
Incorrect Permission Assignment in ASUS System Control Interface
Publication date: 2026-05-29
Last updated on: 2026-05-29
Assigner: ASUS
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| asus | system_control_interface | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Incorrect Permission Assignment for a Critical Resource in the ASUS System Control Interface. It allows a local user to elevate their privileges to SYSTEM level and execute arbitrary code by using a specially crafted RPC call that bypasses the normal validation mechanisms.
How can this vulnerability impact me? :
The vulnerability can allow a local attacker to gain SYSTEM-level privileges, which is the highest level of access on the affected system. This means the attacker can execute any code they want with full control over the system, potentially leading to complete system compromise.