Junglewise Threat Intelligence

CVE-2026-15030: ASUS System Control Interface out-of-bounds read via IOCTL

CVE-2026-15030 · Severity: info · CVSS 5.6 · Published 2026-07-15

Technologies: ASUS System Control Interface v3, ASUS Business Manager, ASUS System Control Interface. Vendors: ASUS.

Executive brief

ASUS System Control Interface and Business Manager are software components used to manage hardware settings and system optimization on ASUS computers. A security vulnerability in these tools could allow a local user with administrative privileges to read sensitive system memory that should normally be protected. This could lead to the exposure of confidential information stored in the computer's firmware or system memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in ASUS System Control Interface (v1 and v3) and ASUS Business Manager. The flaw is located in the handling of Input/Output Control (IOCTL) requests, where the software fails to properly validate the boundaries of memory access requests. A local attacker with high privileges (administrator) can exploit this by sending a specially crafted IOCTL request to bypass validation and read memory regions beyond the intended firmware boundary. This could result in the disclosure of sensitive information from system memory. ASUS has released updates to address this issue in System Control Interface v3.1.65.0 and v1.1.40.0.

Affected products

  • ASUS System Control Interface v3 before v3.1.65.0
  • ASUS System Control Interface before v1.1.40.0
  • ASUS Business Manager up to and including v3.0.38.0

Timeline

  • 2026-07-15: advisory: NVD publication date

References

Related threats