Junglewise Threat Intelligence

CVE-2026-8919: ASUS GameSDK permissive cross-domain policy in local service endpoint

CVE-2026-8919 · Severity: info · CVSS 7.2 · Published 2026-07-15

Vendors: ASUS.

Executive brief

ASUS GameSDK, a software component used for gaming features on ASUS devices, contains a security flaw in how it handles requests from the internet. An attacker can trick a user into visiting a malicious website that forces the software to reveal the user's login credentials (NTLM hashes). This could allow an attacker to impersonate the user on other services, tamper with data, or cause the gaming software to crash.

Technical details

A vulnerability classified as CWE-942 (Permissive Cross-domain Policy with Untrusted Domains) exists in ASUS GameSDK versions V1.0.5 and earlier. The application's local service endpoint fails to properly restrict cross-origin requests, allowing a malicious website to send a request containing a Universal Naming Convention (UNC) path. When the local service attempts to access this UNC path, the Windows operating system automatically sends the user's NTLM credentials to the attacker-controlled server. This can lead to credential theft, potential data tampering, or a denial-of-service condition for the GameSDK component. Users are advised to update to the latest version as specified in the ASUS security advisory.

Affected products

  • ASUS GameSDK <= V1.0.5

Timeline

  • 2026-07-15: advisory: NVD and ASUS published the vulnerability details.

References