ASUS System Control Interface Untrusted Pointer Dereference Vulnerability Allowing Arbitrary Memory Operations

Vulnerability

A vulnerability exists in ASUS System Control Interface versions 3.1.59.0 (x64) and earlier, as well as in ASUS Business Manager versions prior to 3.0.38.0. This vulnerability allows local administrators to perform arbitrary read and write operations on physical memory. The issue arises from an untrusted pointer dereference in the ASUS System Control Interface, which enables the manipulation of memory through crafted IOCTL requests to the driver, bypassing operating system memory protections.

Impact

Exploitation of this vulnerability could lead to unauthorized memory access and manipulation, potentially allowing for the execution of arbitrary code or the introduction of malicious payloads.

Remediation

Users are advised to update to ASUS System Control Interface version 3.1.66.0 or later, and to update ASUS Business Manager to version 3.0.38.0 or later.

Added: Jul 15, 2026, 3:26 AM
Updated: Jul 15, 2026, 3:26 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
1.9
exploitability
2.8
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.