CVE-2025-59373: High severity ASUS System Control Interface vulnerability
A local privilege escalation vulnerability exists in
the restore mechanism of
ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please refer to section Security Update for MyAsus in the ASUS Security Advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59373?
CVE-2025-59373 is classified as a high severity local privilege escalation vulnerability.
How do I fix CVE-2025-59373?
To address CVE-2025-59373, ensure that your ASUS System Control Interface is updated to the latest version provided by ASUS.
What are the potential impacts of CVE-2025-59373?
Exploitation of CVE-2025-59373 could allow an unprivileged user to execute arbitrary files with SYSTEM privileges.
Who is affected by CVE-2025-59373?
CVE-2025-59373 affects users of the ASUS System Control Interface who have not properly applied security updates.
How can I determine if my system is vulnerable to CVE-2025-59373?
You can determine if your system is vulnerable to CVE-2025-59373 by checking the version of ASUS System Control Interface and looking for security patches.