PT-2026-58873 · Asus · Asus Business Manager+1
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ASUS System Control Interface versions 3.0.x
ASUS Business Manager (affected versions not specified)
Description
The ASUS System Control Interface driver and ASUS Business Manager contain issues related to resource allocation without limits and sensitive information remaining in resources before reuse. Specifically, the
bsitf.sys driver fails to validate IOCTL requests, allowing an attacker to map contiguous kernel memory to userspace and leak physical addresses. This can be exploited by a local administrator to disclose sensitive information or cause a system crash (Denial of Service) through pool exhaustion. The issue is linked to reference counter update errors in the IOCTL dispatch handler.Recommendations
Update ASUS System Control Interface version 3.0.x to the latest security update provided by ASUS.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for ASUS Business Manager.
Exploit
Fix
LPE
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asus Business Manager
Asus System Control Interface