CVE-2026-13585
Deferred Deferred - Pending Action

ASUS System Control Interface Driver Resource Exhaustion and Information Disclosure

Vulnerability report for CVE-2026-13585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-21

Assigner: ASUS

Description

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the 'Β  Security Update for ASUS System Control InterfaceΒ Β ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-21
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
asus system_control_interface *
asus business_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-226 The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper resource allocation and failure to remove sensitive information in ASUS System Control Interface and ASUS Business Manager drivers. A local administrator can exploit crafted IOCTL requests to disclose sensitive data or cause a Denial of Service (DoS) on the affected system.

Detection Guidance

This vulnerability involves crafted IOCTL requests in ASUS System Control Interface driver and ASUS Business Manager. Detection requires checking for unusual IOCTL interactions or memory leaks in these components. No specific commands are provided in the context.

Impact Analysis

An attacker with local administrator access could steal sensitive information or crash the system, leading to service disruption. This may affect system stability and confidentiality of data processed by the vulnerable ASUS drivers.

Compliance Impact

This vulnerability could lead to unauthorized disclosure of sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Apply the latest security update for the ASUS System Control Interface driver and ASUS Business Manager as referenced in the ASUS Security Advisory to address the allocation of resources and sensitive information disclosure issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart