CVE-2025-15038
An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15038?
CVE-2025-15038 is classified as a medium-severity vulnerability due to its potential to disclose sensitive kernel information.
How do I fix CVE-2025-15038?
To fix CVE-2025-15038, it is recommended to update the ASUS Business System Control Interface driver to the latest version provided by ASUS.
What systems are affected by CVE-2025-15038?
CVE-2025-15038 affects systems that run the ASUS Business System Control Interface driver.
What is the impact of CVE-2025-15038?
The impact of CVE-2025-15038 could include unauthorized disclosure of kernel information or a potential system crash.
Who can exploit CVE-2025-15038?
CVE-2025-15038 can be exploited by unprivileged local users sending specially crafted IOCTL requests.