Back to CVE List

CVE-2025-15037

Vulnerability Description

An Incorrect
Permission Assignment vulnerability exists in the ASUS Business
System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a
specially crafted IOCTL request,
potentially leading to unauthorized access to sensitive hardware resources
and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-732
Source
NVD
Vendor
ASUS
Product
ASUS Business System Control Interface

External References

Discussion (0)

Add Comment

No comments yet. Be the first!