A local privilege escalation vulnerability exists in
the restore mechanism of
ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM.
For more information, please refer to section Security Update for MyAsus in the ASUS Security Advisory.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.asus.com/content/security-advisory/ |
Configurations
No configuration.
History
25 Nov 2025, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-25 02:15
Updated : 2025-11-25 22:16
NVD link : CVE-2025-59373
Mitre link : CVE-2025-59373
CVE.ORG link : CVE-2025-59373
JSON object : View
Products Affected
No product.
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
