Local Resource Management Vulnerability in ASUS System Control Interface
CVE-2026-13585

8.2HIGH

What is CVE-2026-13585?

CVE-2026-13585 is a vulnerability found in the ASUS System Control Interface, a driver designed for managing system resources within ASUS devices. This vulnerability involves the allocation of resources without proper limits and a failure to remove sensitive information before reuse. As a result, a local administrator could exploit this flaw through crafted IOCTL (Input/Output Control) requests to disclose sensitive data. In more severe scenarios, this vulnerability could lead to a Denial of Service (DoS) condition, which would disrupt normal operations and potentially compromise the availability of the system. Organizations dependent on ASUS products for critical operations must be particularly cautious, as this vulnerability poses risks that can severely impact their operational integrity and data security.

Potential impact of CVE-2026-13585

  1. Sensitive Information Disclosure: The flaw may allow local administrators to access sensitive information due to improper handling of data, posing a risk of data leakage that could be exploited for further attacks or unauthorized access.

  2. Denial of Service (DoS): The vulnerability has the potential to cause service interruptions. An attacker could exploit it to create conditions that render the system inoperable, significantly affecting business continuity and user access.

  3. Unauthorized Resource Management: Given that the vulnerability allows manipulation of system resources without limits, it could lead to unintentional system degradation or instability, affecting the overall performance and reliability of the ASUS products in use within an organization.

Affected Version(s)

Business Manager 0

System Control Interface 0

System Control Interface v3 0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rehman Ahmadzai
.