ASUS System Control Interface and ASUS Business Manager Out-of-Bounds Read Vulnerability

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in ASUS System Control Interface version 3 prior to 3.1.66.0, ASUS System Control Interface earlier than version 1.1.40.0, and ASUS Business Manager prior to version 3.0.38.0. This vulnerability allows a local administrator to read memory regions beyond the intended firmware boundary by sending a crafted IOCTL request that bypasses validation.

Impact

Exploitation of this vulnerability could lead to unauthorized memory access, allowing for potential information disclosure or manipulation.

Remediation

Users are advised to update to ASUS System Control Interface version 3.1.66.0 or later, version 1.1.40.0 or later, and ASUS Business Manager version 3.0.38.0 or later.

Added: Jul 15, 2026, 3:25 AM
Updated: Jul 15, 2026, 3:25 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
2.8
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.