Skip to content
ASUSCVE-2026-13585

ASUS Business Manager: information disclosure

High8.2CVE-2026-13585 · Published Jul 15, 2026 · updated Sep 17, 2026

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.

ASUS advisory

Affected versions

PackageAffectedFixed in
Business Manager
Product
<= through v3.0.38.0No fix yet
System Control Interface
Product
<= before v1.1.40.0No fix yet
System Control Interface v3
Product
<= before v3.1.66.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-226, CWE-770

More ASUS advisories

All ASUS
Advisory
ASUS GameSDK: information disclosure
High7.2Jul 15
ASUS Aura Wallpaper Service: local user could perform file operations
High8.5Jul 15
ASUS Business Manager: untrusted pointer dereference
High8.4Jul 15
ASUS Business Manager: out-of-bounds read
Medium5.6Jul 15
ASUS Router: improper certificate validation
Critical9.5Jul 15
ASUS Router: SQL injection
Medium5.9Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.