Impact
The flaw is an External Control of File Name or Path vulnerability in ASUS Business Manager a tampered, which the application blindly accepts. When processed, the message causes the system to execute arbitrary code with SYSTEM privileges, giving the attacker full control over the host. The weakness maps to CWE‑73 and is assigned a CVSS base score of 8.5.
Affected Systems
ASUS Business Manager, a management solution distributed by ASUS. The advisory does not list a specific version range, indicating that any installation that includes the vulnerable IPC handling code could be affected. The flaw is present in all builds prior to the official security update.
Risk and Exploitability
The CVSS score of 8.5 classifies this as a high‑severity vulnerability. The EPSS score is below 1 % and it is not listed in CISA's KEV catalog. Exploitation requires local access and the creation successfully leveraged, a local attacker can run arbitrary code with SYSTEM rights, effectively becoming a fully privileged user. Although the likelihood is low due to the local access requirement, the impact on the host is catastrophic.
OpenCVE Enrichment