CVE-2025-6398: ASUS Ai Suite

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the ' Security Update for for AI Suite 3 ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Ai Suite: before v3.03.42 (fixed in v3.03.42)

Published 2025-08-01. Last modified 2026-06-17.