VYPR

System Control Interface

by Asus

CVEs (9)

  • CVE-2026-15029HigJul 15, 2026
    risk 0.55cvss epss 0.00

    Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced…

  • CVE-2025-59373HigNov 25, 2025
    risk 0.55cvss epss 0.00

    A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being…

  • CVE-2022-36438HigOct 18, 2022
    risk 0.51cvss 7.8epss 0.00

    AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe…

  • CVE-2026-7480HigMay 29, 2026
    risk 0.47cvss epss 0.00

    An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for…

  • CVE-2025-15038MedMar 12, 2026
    risk 0.45cvss epss 0.00

    An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL  request, potentially leading to a disclosure of kernel information or a system…

  • CVE-2026-3508MedMay 8, 2026
    risk 0.44cvss epss 0.00

    An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more…

  • CVE-2025-15037MedMar 12, 2026
    risk 0.44cvss epss 0.00

    An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive…

  • CVE-2022-36439MedOct 18, 2022
    risk 0.39cvss 6.0epss 0.00

    AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp directory and delete another more privileged file via SYSTEM privileges. This affects ASUS System Control Interface 3 before 3.1.5.0,…

  • CVE-2026-15030MedJul 15, 2026
    risk 0.36cvss epss 0.00

    Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to…