VYPR

Business Manager

by Asus

CVEs (5)

  • CVE-2026-15029HigJul 15, 2026
    risk 0.55cvss —epss 0.00

    Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced…

  • CVE-2026-8921HigJul 3, 2026
    risk 0.55cvss —epss 0.00

    External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for…

  • CVE-2025-13348HigFeb 2, 2026
    risk 0.55cvss —epss 0.00

    An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to…

  • CVE-2026-13585HigJul 15, 2026
    risk 0.53cvss —epss 0.00

    Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests,…

  • CVE-2026-15030MedJul 15, 2026
    risk 0.36cvss —epss 0.00

    Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to…