ASUS GameSDK: information disclosure
High7.2CVE-2026-8919 · Published Jul 15, 2026 · updated Sep 17, 2026
Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK ' section on the ASUS Security Advisory for more information.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GameSDK Product | <= through V1.0.5 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-942
More ASUS advisories
All ASUS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 15 | ASUS Aura Wallpaper Service: local user could perform file operations | High8.5 | No fix yet |
| Jul 15 | ASUS Business Manager: untrusted pointer dereference | High8.4 | No fix yet |
| Jul 15 | ASUS Business Manager: out-of-bounds read | Medium5.6 | No fix yet |
| Jul 15 | ASUS Router: improper certificate validation | Critical9.5 | No fix yet |
| Jul 15 | ASUS Business Manager: information disclosure | High8.2 | No fix yet |
| Jul 15 | ASUS Router: SQL injection | Medium5.9 | No fix yet |