Asus · Asus Business Manager · CVE-2026-8921
**Name of the Vulnerable Software and Affected Versions**
ASUS Business Manager (affected versions not specified)
**Description**
An External Control of File Name or Path issue allows a local user to execute arbitrary code with SYSTEM privileges. This is achieved by tampering with an Inter-Process Communication (IPC) message, which is a mechanism that allows different processes to communicate and synchronize their actions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.