SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-15029

HIGH · CVSS 8.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

ASUS System Control Interface versions 3 and earlier, along with ASUS Business Manager, are vulnerable to an untrusted pointer dereference flaw that allows local administrators to execute arbitrary read and write operations on physical memory through specially crafted IOCTL requests. This vulnerability can lead to significant security breaches by bypassing operating system memory protections. Organizations using affected ASUS products should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-15029
Severity
HIGH
CVSS
8.4
EPSS
0.14%

Original NVD Description

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.