CVE-2026-13585
CVE-2026-13585
8.2
HighPublished:
Last updated:
Source:54bf65a7-a193-42d2-b1ba-8e150d3c35e1
Deferred
CVSS Vector
v4.0- Attack Vector
- Local
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- High
- User Interaction
- None
- Confidentiality (Vulnerable)
- None
- Integrity (Vulnerable)
- None
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- High
Description
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.
References
54bf65a7-a193-42d2-b1ba-8e150d3c35e1
https://www.asus.com/security-advisory/af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2026/Jul/26