CVE-2026-7480: High severity ASUS ASUS System Control Interface vulnerability
An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7480?
CVE-2026-7480 has a severity rating of high, with a CVSS score of 7.3.
How do I fix CVE-2026-7480?
To fix CVE-2026-7480, apply the latest security update provided by ASUS for the System Control Interface.
What does CVE-2026-7480 allow an attacker to do?
CVE-2026-7480 allows a local user to elevate their privileges to SYSTEM and execute arbitrary code.
Who is affected by CVE-2026-7480?
CVE-2026-7480 affects users of the ASUS System Control Interface software.
When was CVE-2026-7480 published?
CVE-2026-7480 was published on May 29, 2026.