CVE-2025-15038: ASUS Business System Control Interface

Medium severity, CVSS 6.9. EPSS: 0.1% chance of exploitation in the next 30 days.

An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL  request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for ASUS  Business System Control Interface" section on the ASUS Security Advisory for more information.

Affected products

  • ASUS ASUS Business System Control Interface: before 0.5.14.0 (fixed in 0.5.14.0)

Published 2026-03-12. Last modified 2026-06-17.