Skip to content
ASUSCVE-2026-8919

ASUS GameSDK: information disclosure

High7.2CVE-2026-8919 · Published Jul 15, 2026 · updated Sep 17, 2026

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK  ' section on the ASUS Security Advisory for more information.

ASUS advisory

Affected versions

PackageAffectedFixed in
GameSDK
Product
<= through V1.0.5No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-942

More ASUS advisories

All ASUS
Advisory
ASUS Aura Wallpaper Service: local user could perform file operations
High8.5Jul 15
ASUS Business Manager: untrusted pointer dereference
High8.4Jul 15
ASUS Business Manager: out-of-bounds read
Medium5.6Jul 15
ASUS Router: improper certificate validation
Critical9.5Jul 15
ASUS Business Manager: information disclosure
High8.2Jul 15
ASUS Router: SQL injection
Medium5.9Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.