---
id: CVE-2026-13585
title: >-
  Allocation of Resources Without Limits and Throttling and Sensitive
  Information in Resource Not Removed Before Reuse in the ASUS System Control
  Interface driver and ASUS Business Manager allow a local administrator to
  disclose sensitive …
summary: >-
  Allocation of Resources Without Limits and Throttling and Sensitive
  Information in Resource Not Removed Before Reuse in the ASUS System Control
  Interface driver and ASUS Business Manager allow a local administrator to
  disclose sensitive …
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H'
cwe:
  - CWE-226
  - CWE-770
vendor: ASUS
product: System Control Interface v3
affected:
  - system_control_interface_v3 before v3.1.66.0
  - system_control_interface before v1.1.40.0
  - business_manager through v3.0.38.0
published: '2026-07-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T09:16:38.583'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13585'
references:
  - url: 'https://www.asus.com/security-advisory/'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
  - url: 'http://seclists.org/fulldisclosure/2026/Jul/26'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00163
epssPercentile: 0.04837
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/416rehman/asus-bsitf-0-day-poc'
  checkedAt: '2026-09-25T08:20:50.110Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-15T13:10:53.177474Z'
cvssSource: cna
ingestedAt: '2026-09-17T09:14:58.446Z'
---

## Overview

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system.
Refer to the ' 
Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
