Description
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message.
Refer to the '
Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
Published: 2026-07-03
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an External Control of File Name or Path vulnerability in ASUS Business Manager a tampered, which the application blindly accepts. When processed, the message causes the system to execute arbitrary code with SYSTEM privileges, giving the attacker full control over the host. The weakness maps to CWE‑73 and is assigned a CVSS base score of 8.5.

Affected Systems

ASUS Business Manager, a management solution distributed by ASUS. The advisory does not list a specific version range, indicating that any installation that includes the vulnerable IPC handling code could be affected. The flaw is present in all builds prior to the official security update.

Risk and Exploitability

The CVSS score of 8.5 classifies this as a high‑severity vulnerability. The EPSS score is below 1 % and it is not listed in CISA's KEV catalog. Exploitation requires local access and the creation successfully leveraged, a local attacker can run arbitrary code with SYSTEM rights, effectively becoming a fully privileged user. Although the likelihood is low due to the local access requirement, the impact on the host is catastrophic.

Generated by OpenCVE AI on July 22, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official ASUS Business Manager security update that addresses the IPC path validation flaw.
  • If the update is not yet available, configure the operating system to run the ASUS Business Manager service under a least‑privilege account and restrict local users from writing to the IPC message directory or endpoint.
  • As a temporary measure, remove group or user write permissions from any files or directories used for IPC communication and ensure only SYSTEM or the service account have write access.

Generated by OpenCVE AI on July 22, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unvalidated IPC Path Enables Local Privilege Escalation in ASUS Business Manager

Wed, 15 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unvalidated IPC Path Enables Local Privilege Escalation in ASUS Business Manager

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title IPC Path Manipulation Allowing SYSTEM Privilege Escalation in ASUS Business Manager

Mon, 13 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title IPC Path Manipulation Allowing SYSTEM Privilege Escalation in ASUS Business Manager

Sun, 12 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 11 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Thu, 09 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Wed, 08 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title External Control of File Path in ASUS Business Manager Enables Local Privilege Escalation

Wed, 08 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title External Control of File Path in ASUS Business Manager Enables Local Privilege Escalation

Tue, 07 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Mon, 06 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Tampering in ASUS Business Manager

Sun, 05 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Tampering in ASUS Business Manager

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 04 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 04 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Sat, 04 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via IPC Path Manipulation in ASUS Business Manager

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local IPC Path Injection Allows SYSTEM Code Execution in ASUS Business Manager

Fri, 03 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local IPC Path Injection Allows SYSTEM Code Execution in ASUS Business Manager

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Description External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus asus Business Manager
Weaknesses CWE-73
CPEs cpe:2.3:a:asus:asus_business_manager:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus asus Business Manager
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Asus Business Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-06T15:42:20.031Z

Reserved: 2026-05-19T05:59:12.172Z

Link: CVE-2026-8921

cve-icon Vulnrichment

Updated: 2026-07-06T15:42:16.297Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-73

    External Control of File Name or Path