CVE-2026-15029: ASUS Business Manager
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.
Affected products
- ASUS Business Manager: up to and including v3.0.38.0
- ASUS System Control Interface: before v1.1.40.0 (fixed in v1.1.40.0)
- ASUS System Control Interface v3: before v3.1.65.0 (fixed in v3.1.65.0)
Published 2026-07-15. Last modified 2026-09-17.