Impact
The ASUS System Control Interface driver and Business Manager contain a flaw where resources are allocated without limits and are not freed before reuse, allowing a local administrator to send crafted IOCTL requests to read data that should be protected. In severe instances the same misuse can exhaust system resources and cause a Denial of Service. The weakness is catalogued as CWE-226 and CWE-770, indicating unchecked resource allocation and exposure of sensitive data before cleanup.
Affected Systems
The affected products are ASUS Business Manager and the ASUS System Control Interface suite, including the System Control Interface v3. The advisory does not list specific versions, so any installation of these components should be treated as vulnerable until a patch release specifies otherwise.
Risk and Exploitability
The issue has a CVSS score of 8.2, marking it high severity, but the EPSS score is less than 1 percent, indicating a very low probability of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is local; a user must possess administrator-level privileges to craft the IOCTL calls. Because the exploitation path is not publicly documented, an exact risk level cannot be precisely determined.
OpenCVE Enrichment