ID

VAR-202210-1645


CVE

CVE-2022-36439


TITLE

plural  ASUSTeK Computer Inc.  Product vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2022-019447

DESCRIPTION

AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.0.45.0. ASUSTeK Computer Inc. of asusliveupdate , asussoftwaremanger , system control interface Exists in unspecified vulnerabilities.Information is tampered with and service operation is interrupted (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2022-36439 // JVNDB: JVNDB-2022-019447 // VULHUB: VHN-432540

AFFECTED PRODUCTS

vendor:asusmodel:system control interfacescope:ltversion:3.1.5.0

Trust: 1.0

vendor:asusmodel:asusliveupdatescope:ltversion:1.0.45.0

Trust: 1.0

vendor:asusmodel:asussoftwaremangerscope:ltversion:1.0.53.0

Trust: 1.0

vendor:asusmodel:system control interfacescope:gteversion:3.0.0.0

Trust: 1.0

vendor:asustek computermodel:asussoftwaremangerscope: - version: -

Trust: 0.8

vendor:asustek computermodel:system control interfacescope: - version: -

Trust: 0.8

vendor:asustek computermodel:asusliveupdatescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-019447 // NVD: CVE-2022-36439

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-36439
value: MEDIUM

Trust: 1.0

NVD: CVE-2022-36439
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202210-1188
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2022-36439
baseSeverity: MEDIUM
baseScore: 6.0
vectorString: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2022-36439
baseSeverity: MEDIUM
baseScore: 6.0
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-019447 // CNNVD: CNNVD-202210-1188 // NVD: CVE-2022-36439

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-019447 // NVD: CVE-2022-36439

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202210-1188

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202210-1188

PATCH

title:ASUS System Control Interface Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=211489

Trust: 0.6

sources: CNNVD: CNNVD-202210-1188

EXTERNAL IDS

db:NVDid:CVE-2022-36439

Trust: 3.3

db:JVNDBid:JVNDB-2022-019447

Trust: 0.8

db:CNNVDid:CNNVD-202210-1188

Trust: 0.6

db:VULHUBid:VHN-432540

Trust: 0.1

sources: VULHUB: VHN-432540 // JVNDB: JVNDB-2022-019447 // CNNVD: CNNVD-202210-1188 // NVD: CVE-2022-36439

REFERENCES

url:https://asus.com

Trust: 2.5

url:https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedrive.aspx?id=%2fpersonal%2fcarinacw_li_asus_com%2fdocuments%2fsecurity%2fcase-220713%2fasus%20arbitary%20file%20deletion.pdf&parent=%2fpersonal%2fcarinacw_li_asus_com%2fdocuments%2fsecurity%2fcase-220713&ga=1

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2022-36439

Trust: 0.8

url:https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedrive.aspx?id=%2fpersonal%2fcarinacw%5fli%5fasus%5fcom%2fdocuments%2fsecurity%2fcase%2d220713%2fasus%20arbitary%20file%20deletion%2epdf&parent=%2fpersonal%2fcarinacw%5fli%5fasus%5fcom%2fdocuments%2fsecurity%2fcase%2d220713&ga=1

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-36439/

Trust: 0.6

url:https://asus-my.sharepoint.com/personal/carinacw_li_asus_com/_layouts/15/onedrive.aspx?id=%2fpersonal%2fcarinacw%5fli%5fasus%5fcom%2fdocuments%2fsecurity%2fcase%2d220713%2fasus%20arbitary%20file%20deletion%2epdf&parent=%2fpersonal%2fcarinacw%5fli%5fasus%5fcom%2fdocuments%2fsecurity%2fcase%2d220713&ga=1

Trust: 0.1

sources: VULHUB: VHN-432540 // JVNDB: JVNDB-2022-019447 // CNNVD: CNNVD-202210-1188 // NVD: CVE-2022-36439

SOURCES

db:VULHUBid:VHN-432540
db:JVNDBid:JVNDB-2022-019447
db:CNNVDid:CNNVD-202210-1188
db:NVDid:CVE-2022-36439

LAST UPDATE DATE

2024-08-14T14:30:56.461000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-432540date:2022-10-20T00:00:00
db:JVNDBid:JVNDB-2022-019447date:2023-10-25T08:14:00
db:CNNVDid:CNNVD-202210-1188date:2022-10-24T00:00:00
db:NVDid:CVE-2022-36439date:2023-11-07T03:49:38.340

SOURCES RELEASE DATE

db:VULHUBid:VHN-432540date:2022-10-18T00:00:00
db:JVNDBid:JVNDB-2022-019447date:2023-10-25T00:00:00
db:CNNVDid:CNNVD-202210-1188date:2022-10-18T00:00:00
db:NVDid:CVE-2022-36439date:2022-10-18T12:15:09.473