ASUS Business Manager Secure Delete Driver Improper Access Control Vulnerability

Vulnerability

A vulnerability allowing improper access control has been identified in the ASUS Secure Delete Driver within ASUS Business Manager versions through 3.0.36.0. This vulnerability can be exploited by a local user who sends a specially crafted request, potentially leading to the creation of arbitrary files in a specified location.

Impact

Exploitation of this vulnerability could result in unauthorized file creation, allowing for potential manipulation or misuse of the created files.

Remediation

Users are advised to update to ASUS Business Manager version 3.0.36.0 or later.

Added: Feb 2, 2026, 2:21 AM
Updated: Feb 2, 2026, 2:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
3.3
remediation
0.0
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.