CVE-2025-15038

MEDIUM

ASUS Business System Control Interface - Info Disclosure

Title source: llm

Description

An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL  request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for ASUS  Business System Control Interface" section on the ASUS Security Advisory for more information.

Scores

CVSS v4 6.9
EPSS 0.0002
EPSS Percentile 4.8%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

Details

CWE
CWE-125
Status published
Products (1)
ASUS/ASUS Business System Control Interface < 0.5.14.0
Published Mar 12, 2026
Tracked Since Mar 12, 2026