CVE-2026-3508
Awaiting Analysis Awaiting Analysis - Queue
Out-of-bounds Read in ASUS System Control Interface

Publication date: 2026-05-08

Last updated on: 2026-05-08

Assigner: ASUS

Description
An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUSΒ ' section on the ASUS Security Advisory for more information.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-08
Last Modified
2026-05-08
Generated
2026-06-19
AI Q&A
2026-05-08
EPSS Evaluated
2026-06-18
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
asus myasus *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an Out-of-bounds Read in the IOCTL handler of the ASUS System Control Interface. It allows a local user to cause a system crash (Blue Screen of Death) by performing a read operation that exceeds the allocated buffer size.

Impact Analysis

The impact of this vulnerability is that a local user can cause the system to crash unexpectedly, leading to potential denial of service. This can disrupt normal operations and may require a system reboot to recover.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3508. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart