Description
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message.
Refer to the '
Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
Published: 2026-07-03
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

External Control of File Name or Path in ASUS Business Manager lets a local user send a tampered IPC message that the application blindly accepts. When processed, the message causes the system to execute arbitrary code with SYSTEM privileges, effectively giving the attacker full control over the host. This flaw corresponds to CWE‑73 and is assigned a CVSS base score of 8.5.

Affected Systems

ASUS Business Manager, a management solution from ASUS. The security advisory does not specify a version range, indicating that any deployment containing the vulnerable IPC handling code prior to the vendor’s security update may be affected.

Risk and Exploitability

The CVSS score of 8.5 classifies the vulnerability as high‑severity. The EPSS score is below 1 % and it is not listed in the CISA KEV catalog, suggesting a low probability of exploitation in the broader threat landscape. However, exploitation requires local access; an attacker who is able to run locally can craft a malicious IPC message that triggers arbitrary code execution with SYSTEM privileges, resulting in full compromise of the host.

Generated by OpenCVE AI on August 3, 2026 at 05:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official ASUS Business Manager security update that addresses the IPC path validation flaw.
  • If the update is not yet available, configure the ASUS Business Manager service to run under a least‑privilege account and restrict local users from writing to the IPC message directory or endpoint.
  • As a temporary measure, remove group or user write permissions from any files or directories used for IPC communication so that only SYSTEM or the dedicated service account has write access.

Generated by OpenCVE AI on August 3, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 03 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local IPC Path Manipulation Allows System‑Level Code Execution

Wed, 29 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local IPC Path Manipulation Allows System‑Level Code Execution

Sun, 26 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title External Control of File Name or Path Allows Local Privilege Escalation in ASUS Business Manager

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title External Control of File Name or Path Allows Local Privilege Escalation in ASUS Business Manager

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unvalidated IPC Path Enables Local Privilege Escalation in ASUS Business Manager

Wed, 15 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unvalidated IPC Path Enables Local Privilege Escalation in ASUS Business Manager

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title IPC Path Manipulation Allowing SYSTEM Privilege Escalation in ASUS Business Manager

Mon, 13 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title IPC Path Manipulation Allowing SYSTEM Privilege Escalation in ASUS Business Manager

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 11 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Thu, 09 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Wed, 08 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title External Control of File Path in ASUS Business Manager Enables Local Privilege Escalation

Wed, 08 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title External Control of File Path in ASUS Business Manager Enables Local Privilege Escalation

Tue, 07 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Mon, 06 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Tampering in ASUS Business Manager

Sun, 05 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Tampering in ASUS Business Manager

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 04 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 04 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 04 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local IPC Path Injection Allows SYSTEM Code Execution in ASUS Business Manager

Fri, 03 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local IPC Path Injection Allows SYSTEM Code Execution in ASUS Business Manager

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Description External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus asus Business Manager
Weaknesses CWE-73
CPEs cpe:2.3:a:asus:asus_business_manager:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus asus Business Manager
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Asus Business Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-06T15:42:20.031Z

Reserved: 2026-05-19T05:59:12.172Z

Link: CVE-2026-8921

cve-icon Vulnrichment

Updated: 2026-07-06T15:42:16.297Z

cve-icon NVD

Status : Deferred

Published: 2026-07-03T03:16:23.627

Modified: 2026-07-06T18:56:27.910

Link: CVE-2026-8921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:45:03Z

Weaknesses
  • CWE-73

    External Control of File Name or Path