Impact
External Control of File Name or Path in ASUS Business Manager lets a local user send a tampered IPC message that the application blindly accepts. When processed, the message causes the system to execute arbitrary code with SYSTEM privileges, effectively giving the attacker full control over the host. This flaw corresponds to CWE‑73 and is assigned a CVSS base score of 8.5.
Affected Systems
ASUS Business Manager, a management solution from ASUS. The security advisory does not specify a version range, indicating that any deployment containing the vulnerable IPC handling code prior to the vendor’s security update may be affected.
Risk and Exploitability
The CVSS score of 8.5 classifies the vulnerability as high‑severity. The EPSS score is below 1 % and it is not listed in the CISA KEV catalog, suggesting a low probability of exploitation in the broader threat landscape. However, exploitation requires local access; an attacker who is able to run locally can craft a malicious IPC message that triggers arbitrary code execution with SYSTEM privileges, resulting in full compromise of the host.
OpenCVE Enrichment