Security Advisory

CVE-2025-15037

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-12 02:00:20
Last updated 2026-03-12 13:15:55
Assigner ASUS
State PUBLISHED

Description

An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.