CVE-2025-15038

Severity CVSS v4.0:
MEDIUM
Type:
CWE-125 Out-of-bounds Read
Publication date:
12/03/2026
Last modified:
12/03/2026

Description

An Out-of-Bounds<br /> Read vulnerability exists in the ASUS Business System<br /> Control Interface driver. This vulnerability can be triggered by an unprivileged local user<br /> sending a specially crafted IOCTL  request, potentially leading<br /> to a disclosure of<br /> kernel information or a system crash. Refer to the "Security Update for ASUS <br /> Business System Control Interface" section on the ASUS Security Advisory for more information.

References to Advisories, Solutions, and Tools