Description
An Incorrect
Permission Assignment vulnerability exists in the ASUS Business
System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a
specially crafted IOCTL request,
potentially leading to unauthorized access to sensitive hardware resources
and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.
Published: 2026-03-12
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Information Disclosure
Action: Apply Update
AI Analysis

Impact

An incorrect permission assignment in the ASUS Business System Control Interface driver permits an unprivileged local user to craft an IOCTL request that results in unauthorized access to sensitive hardware resources and kernel information disclosure. The vulnerability manifests as an Access Control failure (CWE-732) where the driver fails to verify the caller's privileges before performing privileged operations. In practice, a local attacker could read kernel memory or sensitive device registers, potentially leaking confidential data without achieving remote code execution or system-wide compromise.

Affected Systems

The vulnerability affects the ASUS Business System Control Interface product from ASUS. Specific affected versions are not listed in the CVE data; therefore, all versions of the driver may be at risk unless an update is applied.

Risk and Exploitability

The CVSS score of 6.8 reflects a moderate severity, with the main risks including confidentiality impact and limited integrity impact. EPSS shows a probability of exploitation of less than 1%, indicating low likelihood of discovery and use at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred as local, requiring the attacker to be able to execute code on the same machine and have privileges to send IOCTL requests; thus, remote exploitation is not possible based on the information provided.

Generated by OpenCVE AI on March 18, 2026 at 14:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the ASUS website for the latest driver or firmware update for the Business System Control Interface and install it.
  • Restrict local user accounts from executing the vulnerable IOCTL interface or limit them to non‑privileged roles wherever possible.
  • If the environment allows, disable the Business System Control Interface service or physical interface that exposes the vulnerable driver.
  • Enable and monitor kernel audit logs to detect anomalous IOCTL calls or unexpected driver activity.
  • Subscribe to ASUS security advisories to stay informed of future patches or additional mitigations.

Generated by OpenCVE AI on March 18, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unprivileged Local Access to Kernel Information via ASUS Business System Control Interface Driver

Thu, 12 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Description An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus asus Business System Control Interface
Weaknesses CWE-732
CPEs cpe:2.3:a:asus:asus_business_system_control_interface:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus asus Business System Control Interface
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Asus Asus Business System Control Interface
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-03-12T13:15:55.928Z

Reserved: 2025-12-23T06:48:49.410Z

Link: CVE-2025-15037

cve-icon Vulnrichment

Updated: 2026-03-12T13:15:52.576Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-12T03:15:56.353

Modified: 2026-03-12T21:07:53.427

Link: CVE-2025-15037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T15:36:15Z

Weaknesses