An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the '
Security Update for MyASUS ' section on the ASUS Security Advisory for more information.
Security Update for MyASUS ' section on the ASUS Security Advisory for more information.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.asus.com/security-advisory |
|
History
Fri, 08 May 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Asus system Control Interface
|
|
| Vendors & Products |
Asus system Control Interface
|
Fri, 08 May 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information. | |
| First Time appeared |
Asus
Asus asus System Control Interface |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:asus:asus_system_control_interface:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Asus
Asus asus System Control Interface |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ASUS
Published:
Updated: 2026-05-08T02:00:53.822Z
Reserved: 2026-03-04T05:51:48.969Z
Link: CVE-2026-3508
No data.
Status : Received
Published: 2026-05-08T03:16:24.820
Modified: 2026-05-08T03:16:24.820
Link: CVE-2026-3508
No data.
OpenCVE Enrichment
Updated: 2026-05-08T04:15:26Z
Weaknesses