{"id":"CVE-2026-13585","title":"Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …","summary":"Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive …","severity":"high","cvss":8.2,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H","cwe":["CWE-226","CWE-770"],"vendor":"ASUS","product":"System Control Interface v3","affected":["system_control_interface_v3 before v3.1.66.0","system_control_interface before v1.1.40.0","business_manager through v3.0.38.0"],"published":"2026-07-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T09:16:38.583","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13585","references":[{"url":"https://www.asus.com/security-advisory/","label":"54bf65a7-a193-42d2-b1ba-8e150d3c35e1"},{"url":"http://seclists.org/fulldisclosure/2026/Jul/26","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.00163,"epssPercentile":0.05921,"exploits":{"github":1,"githubRepos":["https://github.com/416rehman/asus-bsitf-0-day-poc"],"checkedAt":"2026-09-24T07:52:57.742Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-15T13:10:53.177474Z"},"cvssSource":"cna","ingestedAt":"2026-09-17T09:14:58.446Z","slug":"CVE-2026-13585","body":"## Overview\n\nAllocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system.\nRefer to the ' \nSecurity Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":45.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}