CVE-2025-15037Disclosure

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information disclosure. Refer to the "ASUS Business System Control Interface" section on the ASUS Security Advisory for more information.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-18: 103-1203-18
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure1General1
2026-03-181
Patch1
Full discourse3 posts
  • Julian Horoszkiewicz@ewilded
    Patch

    Two more kernel-mode CVEs: CVE-2025-15037, CVE-2025-15038 (ASUS Business System Control Interface) 😉 https://www.asus.com/security-advisory https://t.co/mjvuq28vDT

    Post summary

    ASUS has issued a security advisory for two kernel‑mode CVEs affecting its Business System Control Interface, with patch details available on the company’s site.

    0000078
    47 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-15037 📊 Severity: 6.8 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-15037 #CVE-2025-15037 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/iXbNYShHwO

    Post summary

    The tweet announces CVE-2025-15037 with a medium severity rating but offers no additional technical, exploitation, or patch information.

    0000098
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15037 An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged l… https://www.cve.org/CVERecord?id=CVE-2025-15037

    Post summary

    The text announces a new ASUS driver vulnerability (CVE-2025-15037) and links to its CVE page, providing a brief technical description but no exploits, patches, or active‑use evidence.

    00000126
    56.7K followersView on X

Explore more