CVE-2026-15029: High severity ASUS ASUS System Control Interface vulnerability
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15029?
CVE-2026-15029 has a severity rating of high with a CVSS score of 8.4.
How do I fix CVE-2026-15029?
To mitigate CVE-2026-15029, update to the latest version of the ASUS System Control Interface and ASUS Business Manager as recommended in the security advisory.
What is CVE-2026-15029?
CVE-2026-15029 is a vulnerability in ASUS System Control Interface that allows a local attacker to perform arbitrary read and write operations on physical memory.
Who is affected by CVE-2026-15029?
CVE-2026-15029 affects users of ASUS System Control Interface, including versions v3 and ASUS Business Manager on supported systems.
What type of attack does CVE-2026-15029 enable?
CVE-2026-15029 enables an attack where a local administrator can bypass OS memory protections through crafted IOCTL requests.