Junglewise Threat Intelligence

CVE-2026-13585: ASUS System Control Interface and Business Manager Information Disclosure and DoS

CVE-2026-13585 · Severity: info · CVSS 8.2 · Published 2026-07-15

Technologies: ASUS System Control Interface v3, ASUS Business Manager, ASUS System Control Interface. Vendors: ASUS.

Executive brief

A security vulnerability exists in the ASUS System Control Interface and ASUS Business Manager, which are tools used to manage hardware settings and system performance on ASUS computers. A local user with administrative privileges could exploit this flaw to access sensitive system information or cause the computer to crash or become unresponsive. ASUS has released software updates to address these issues and restore system stability.

Technical details

The vulnerability encompasses two primary issues: 'Allocation of Resources Without Limits or Throttling' (CWE-770) and 'Sensitive Information in Resource Not Removed Before Reuse' (CWE-226) within the ASUS System Control Interface driver and ASUS Business Manager. A local attacker with high privileges (Administrator) can trigger these flaws by sending specially crafted Input/Output Control (IOCTL) requests to the affected driver. Successful exploitation allows the attacker to disclose sensitive system information or trigger a system-wide Denial of Service (DoS). ASUS has addressed these vulnerabilities in System Control Interface v3 (v3.1.66.0), System Control Interface (v1.1.40.0), and Business Manager (versions newer than v3.0.38.0).

Affected products

  • ASUS System Control Interface v3 less than v3.1.66.0
  • ASUS System Control Interface less than v1.1.40.0
  • ASUS Business Manager less than or equal to v3.0.38.0

Timeline

  • 2026-07-15: advisory: NVD publication date
  • 2026-07-14: disclosed: ASUS reported the CVE to NVD

References

Related threats