ASUS System Control Interface
cpe:2.3:a:asus:system_control_interface:*:*:*:*:*:*:*
- < 3.1.66.0
- < 1.1.40.0
A vulnerability exists in the ASUS System Control Interface driver and ASUS Business Manager, allowing local administrators to disclose sensitive information through crafted IOCTL requests. This issue arises from the allocation of resources without proper limits and throttling, coupled with sensitive information not being removed before reuse. In severe cases, this vulnerability may lead to a denial-of-service condition on the system.
Exploitation of this vulnerability could result in unauthorized disclosure of sensitive information, with the potential for causing a denial-of-service condition on the system.
Users can refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for guidance on applying the latest update.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.