CVE-2026-3508: ASUS System Control Interface
Medium severity, CVSS 6.8. EPSS: 0.1% chance of exploitation in the next 30 days.
An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information.
Affected products
- ASUS ASUS System Control Interface: up to and including V3.1.59.1
Published 2026-05-08. Last modified 2026-09-17.