Description
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections.
Refer to the ' 
Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
Published: 2026-07-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted pointer dereference flaw in ASUS System Control Interface v3, ASUS System Control Interface and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests, bypassing operating‑system memory protection.

Affected Systems

ASUS Business Manager and ASUS System Control Interface (including v3) are affected. The advisory does not list specific release numbers, so any installation containing the referenced drivers should be evaluated as potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates a high‑severity risk. The EPSS score of < 1 % suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local administrator executing crafted IOCTL calls, so the threat is limited to users with local elevated privileges, though a compromised local account could also exploit it.

Generated by OpenCVE AI on August 3, 2026 at 03:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the ASUS security update for the System Control Interface and Business Manager as soon as it becomes available
  • Limit local administrator privileges or treat the vulnerable driver as a restricted resource
  • Disable or remove the driver if it is not required for operational needs
  • Monitor system logs for abnormal IOCTL activity that could indicate exploitation attempts

Generated by OpenCVE AI on August 3, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 03 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Local Physical Memory Read/Write via IOCTL in ASUS System Control Interface

Wed, 29 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Local Physical Memory Read/Write via IOCTL in ASUS System Control Interface

Sun, 26 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local Admin Physical Memory Read/Write via Pointer Dereference in ASUS System Control Interface

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Admin Physical Memory Read/Write via Pointer Dereference in ASUS System Control Interface

Fri, 17 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Untrusted Pointer Dereference Enabling Arbitrary Physical Memory Access in ASUS System Control Interface

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Untrusted Pointer Dereference Enabling Arbitrary Physical Memory Access in ASUS System Control Interface

Wed, 15 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus business Manager
Asus system Control Interface
Asus system Control Interface V3
Weaknesses CWE-822
CPEs cpe:2.3:a:asus:business_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:system_control_interface:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:system_control_interface_v3:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus business Manager
Asus system Control Interface
Asus system Control Interface V3
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Business Manager System Control Interface System Control Interface V3
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-15T14:23:38.260Z

Reserved: 2026-07-08T07:18:44.846Z

Link: CVE-2026-15029

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference