ASUS System Control Interface
cpe:2.3:a:asus:system_control_interface:*:*:*:*:*:*:*
- < 3.1.66.0
- < 1.1.40.0
A vulnerability exists in ASUS System Control Interface versions 3.1.59.0 (x64) and earlier, as well as in ASUS Business Manager versions prior to 3.0.38.0. This vulnerability allows local administrators to perform arbitrary read and write operations on physical memory. The issue arises from an untrusted pointer dereference in the ASUS System Control Interface, which enables the manipulation of memory through crafted IOCTL requests to the driver, bypassing operating system memory protections.
Exploitation of this vulnerability could lead to unauthorized memory access and manipulation, potentially allowing for the execution of arbitrary code or the introduction of malicious payloads.
Users are advised to update to ASUS System Control Interface version 3.1.66.0 or later, and to update ASUS Business Manager to version 3.0.38.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.