CVE-2026-15030: Medium severity ASUS ASUS System Control Interface vulnerability
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15030?
The severity of CVE-2026-15030 is classified as medium with a CVSS score of 5.6.
What are the potential impacts of CVE-2026-15030?
CVE-2026-15030 allows a local administrator to read memory regions beyond the firmware boundary, which can lead to information disclosure.
How do I fix CVE-2026-15030?
To fix CVE-2026-15030, update to the latest version of the ASUS System Control Interface or ASUS Business Manager as per the security advisory.
Who is affected by CVE-2026-15030?
CVE-2026-15030 affects users of ASUS System Control Interface and ASUS Business Manager software.
What is the cause of CVE-2026-15030?
CVE-2026-15030 is caused by an out-of-bounds read vulnerability that occurs when a crafted IOCTL request bypasses validation.