CVE-2026-15029: ASUS Business Manager

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.

Affected products

  • ASUS Business Manager: up to and including v3.0.38.0
  • ASUS System Control Interface: before v1.1.40.0 (fixed in v1.1.40.0)
  • ASUS System Control Interface v3: before v3.1.65.0 (fixed in v3.1.65.0)

Published 2026-07-15. Last modified 2026-09-17.