CVE-2025-12793

Severity CVSS v4.0:
HIGH
Type:
CWE-426 Untrusted Search Path
Publication date:
06/01/2026
Last modified:
28/01/2026

Description

An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution.<br /> Refer to the &amp;#39;<br /> <br /> Security Update for MyASUS&amp;#39; section on the ASUS Security Advisory for more information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asus:myasus:*:*:*:*:*:*:x64:* 4.0.52.0 (excluding)
cpe:2.3:a:asus:myasus:*:*:*:*:*:*:arm64:* 4.2.50.0 (excluding)