PT-2026-58874 · Asus · Asus Business Manager+2
CVE-2026-15029
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ASUS System Control Interface v3 (affected versions not specified)
ASUS System Control Interface (affected versions not specified)
ASUS Business Manager (affected versions not specified)
Description
An untrusted pointer dereference exists in the driver, allowing a local administrator to execute arbitrary physical memory read and write operations. This is achieved by sending crafted IOCTL (Input/Output Control) requests to the driver, which enables the bypass of memory protections enforced by the operating system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Business Manager
Asus System Control Interface
System Control Interface V3