Asus System Control Interface vulnerabilities
5 known vulnerabilities affecting asus/system_control_interface.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-15029P3HIGHCVSS 8.4fixed in v1.1.40.02026-07-15
CVE-2026-15029 [HIGH] CWE-822 CVE-2026-15029: Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, an
Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections.
Refer to the '
Security Update for ASUS System Contro
nvd
CVE-2022-36438P3HIGHCVSS 7.8≥ 3.0.0.0, < 3.1.5.02022-10-18
CVE-2022-36438 [HIGH] CWE-276 CVE-2022-36438: AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to l
AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe before 1.0.10.0.
nvd
CVE-2026-13585P3HIGHCVSS 8.2fixed in v1.1.40.02026-07-15
CVE-2026-13585 [HIGH] CWE-226 CVE-2026-13585: Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Remo
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system.
nvd
CVE-2022-36439P4MEDIUMCVSS 6.0≥ 3.0.0.0, < 3.1.5.02022-10-18
CVE-2022-36439 [MEDIUM] CWE-276 CVE-2022-36439: AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0, AsusSoftwareManger.exe before 1.0.53.0, and AsusLiveUpdate.dll before 1.
nvd
CVE-2026-15030P4MEDIUMCVSS 5.6fixed in v1.1.40.02026-07-15
CVE-2026-15030 [MEDIUM] CWE-125 CVE-2026-15030: Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Busi
Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation.
Refer to the ' Security Update for ASUS System Control Interface ' section on the
nvd