Impact
An untrusted pointer dereference flaw in ASUS System Control Interface v3, ASUS System Control Interface and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests, bypassing operating‑system memory protection.
Affected Systems
ASUS Business Manager and ASUS System Control Interface (including v3) are affected. The advisory does not list specific release numbers, so any installation containing the referenced drivers should be evaluated as potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity risk. The EPSS score of < 1 % suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local administrator executing crafted IOCTL calls, so the threat is limited to users with local elevated privileges, though a compromised local account could also exploit it.
OpenCVE Enrichment