ASUS System Control Interface v3是中国ASUS公司的一款系统控制界面管理软件。 ASUS System Control Interface v3存在缓冲区错误漏洞,源于不受信任的指针取消引用,允许本地管理员通过特制的IOCTL请求对驱动程序执行任意物理内存读写操作,绕过操作系统强制内存保护。以下版本受到影响:ASUS System Control Interface v3 v3.1.65.0之前版本、ASUS System Control Interface v1.1.40
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ASUS | Business Manager | through v3.0.38.0 |
affected |
| ASUS | System Control Interface | before v1.1.40.0 |
affected |
| ASUS | System Control Interface v3 | before v3.1.65.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ASUS | System Control Interface v3 | before v3.1.65.0 | - |
|
| ASUS | System Control Interface | before v1.1.40.0 | - |
|
| ASUS | Business Manager | through v3.0.38.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13385 | 9.5 CRITICAL | ASUS Router 加密问题漏洞 |
| CVE-2026-13585 | 8.2 HIGH | ASUS System Control Interface v3 资源管理错误漏洞 |
| CVE-2026-8919 | 7.2 HIGH | ASUS GameSDK 配置错误漏洞 |
| CVE-2026-15030 | 5.6 MEDIUM | ASUS System Control Interface v3 缓冲区错误漏洞 |
| CVE-2026-11851 | ASUS Router SQL注入漏洞 | |
| CVE-2026-8920 | ASUS Aura Wallpaper Service 输入验证错误漏洞 |
No comments yet