CVE-2026-13585: High severity ASUS ASUS System Control Interface driver vulnerability
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13585?
The severity of CVE-2026-13585 is rated as high with a CVSS score of 8.2.
How do I fix CVE-2026-13585?
To fix CVE-2026-13585, users should update the ASUS System Control Interface driver and ASUS Business Manager to the latest version provided by ASUS.
What type of vulnerability is CVE-2026-13585?
CVE-2026-13585 is an allocation of resources without limits and throttling, leading to potential sensitive information disclosure.
Who is affected by CVE-2026-13585?
Local administrators using ASUS System Control Interface driver and ASUS Business Manager may be affected by CVE-2026-13585.
What kind of information could be disclosed due to CVE-2026-13585?
CVE-2026-13585 allows a local administrator to disclose sensitive information through crafted IOCTL requests.