---
id: CVE-2026-8919
title: >-
  Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK
  allows a remote user to obtain a local user’s NTLM hash by convincing the user
  to visit a crafted web page that sends a request containing a UNC path to the
  a…
summary: >-
  Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK
  allows a remote user to obtain a local user’s NTLM hash by convincing the user
  to visit a crafted web page that sends a request containing a UNC path to the
  a…
severity: high
cvss: 7.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L'
cwe:
  - CWE-942
vendor: ASUS
product: GameSDK
affected:
  - GameSDK through V1.0.5
published: '2026-07-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T09:16:42.947'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8919'
references:
  - url: 'https://www.asus.com/security-advisory/'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
tags:
  - nvd
  - cve.org
epss: 0.00447
epssPercentile: 0.3827
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-07-15T12:34:07.016976Z'
cvssSource: cna
ingestedAt: '2026-09-17T09:14:58.448Z'
---

## Overview

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services.
Refer to the ' Security Update for ASUS GameSDK  ' section on the ASUS Security Advisory for more information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
