ASUS System Control Interface and ASUS Business Manager Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability exists in the ASUS System Control Interface driver and ASUS Business Manager, allowing local administrators to disclose sensitive information through crafted IOCTL requests. This issue arises from the allocation of resources without proper limits and throttling, coupled with sensitive information not being removed before reuse. In severe cases, this vulnerability may lead to a denial-of-service condition on the system.

Impact

Exploitation of this vulnerability could result in unauthorized disclosure of sensitive information, with the potential for causing a denial-of-service condition on the system.

Remediation

Users can refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for guidance on applying the latest update.

Added: Jul 15, 2026, 3:26 AM
Updated: Jul 15, 2026, 3:26 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
1.7
exploitability
2.8
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.