CVE-2025-15038
MEDIUMASUS Business System Control Interface - Info Disclosure
Title source: llmDescription
An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.
Scores
CVSS v4
6.9
EPSS
0.0002
EPSS Percentile
4.8%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
Details
CWE
CWE-125
Status
published
Products (1)
ASUS/ASUS Business System Control Interface
< 0.5.14.0
Published
Mar 12, 2026
Tracked Since
Mar 12, 2026