CVE-2026-7480: ASUS System Control Interface

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS ASUS System Control Interface: up to and including 3.1.59.0; up to and including 3.2.60.0

Published 2026-05-29. Last modified 2026-07-21.