CVE-2025-15038
Severity CVSS v4.0:
MEDIUM
Type:
CWE-125
Out-of-bounds Read
Publication date:
12/03/2026
Last modified:
12/03/2026
Description
An Out-of-Bounds<br />
Read vulnerability exists in the ASUS Business System<br />
Control Interface driver. This vulnerability can be triggered by an unprivileged local user<br />
sending a specially crafted IOCTL request, potentially leading<br />
to a disclosure of<br />
kernel information or a system crash. Refer to the "Security Update for ASUS <br />
Business System Control Interface" section on the ASUS Security Advisory for more information.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM



