Junglewise Threat Intelligence

CVE-2026-15029: ASUS System Control Interface Untrusted Pointer Dereference

CVE-2026-15029 · Severity: info · CVSS 8.4 · Published 2026-07-15

Technologies: ASUS System Control Interface v3, ASUS System Control Interface, ASUS Business Manager. Vendors: ASUS.

Executive brief

A vulnerability in ASUS system management software could allow a user with administrative privileges to bypass standard operating system security protections. By interacting with a specific software driver, an attacker could gain unauthorized access to the computer's physical memory. This could lead to the theft of sensitive data or the ability to modify critical system operations, potentially compromising the entire device.

Technical details

An untrusted pointer dereference vulnerability (CWE-822) exists in the drivers for ASUS System Control Interface (v1 and v3) and ASUS Business Manager. A local attacker with administrative privileges can send specially crafted Input/Output Control (IOCTL) requests to the affected driver. This allows the attacker to bypass OS-enforced memory protections and perform arbitrary read and write operations directly to physical memory. Such access can be used to escalate privileges further or compromise the kernel. ASUS has released updates to address this issue in System Control Interface v3.1.65.0, v1.1.40.0, and Business Manager versions following v3.0.38.0.

Affected products

  • ASUS System Control Interface v3 less than v3.1.65.0
  • ASUS System Control Interface less than v1.1.40.0
  • ASUS Business Manager less than or equal to v3.0.38.0

Timeline

  • 2026-07-15: disclosed: CVE published by ASUS/NVD

References