Report: CVE-2025-15037 - ASUS Business System Control Interface Privilege Escalation Vulnerability

Report: CVE-2025-15037 - ASUS Business System Control Interface Privilege Escalation Vulnerability

CVE ID :CVE-2025-15037 Published : March 12, 2026, 3:15 a.m. | 27 minutes ago Description :An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information disclosure. Refer to the

CVE Details

Published
March 12, 2026
Attack Vector: local
Impact: information disclosure