CVE-2026-15029
Deferred Deferred - Pending Action

Untrusted Pointer Dereference in ASUS System Control Interface

Vulnerability report for CVE-2026-15029, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-15

Assigner: ASUS

Description

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the 'Β  Security Update for ASUS System Control InterfaceΒ Β ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-15
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
asus system_control_interface 3
asus business_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager. It allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections.

Detection Guidance

This vulnerability involves arbitrary physical memory read/write via crafted IOCTL requests to ASUS drivers. Detection requires checking for suspicious IOCTL interactions with ASUS System Control Interface or ASUS Business Manager drivers. Use tools like Process Monitor to monitor driver activity or inspect loaded drivers with 'driverquery' in Command Prompt. Look for unexpected memory access patterns or unauthorized driver interactions.

Impact Analysis

This vulnerability allows a local administrator to read or write arbitrary physical memory, potentially leading to privilege escalation, data theft, or system compromise. It bypasses OS protections, making it highly dangerous.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA compliance requirements for data protection and confidentiality.

Mitigation Strategies

Apply the security update for ASUS System Control Interface as referenced in the ASUS Security Advisory to address the untrusted pointer dereference issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15029. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart