CVE-2025-15037
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/03/2026
Last modified:
12/03/2026
Description
An Incorrect<br />
Permission Assignment vulnerability exists in the ASUS Business<br />
System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a<br />
specially crafted IOCTL request,<br />
potentially leading to unauthorized access to sensitive hardware resources<br />
and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM



