Description
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system.
Refer to the ' 
Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
Published: 2026-07-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ASUS System Control Interface driver and Business Manager contain a flaw where resources are allocated without limits and are not freed before reuse, allowing a local administrator to send crafted IOCTL requests to read data that should be protected. In severe instances the same misuse can exhaust system resources and cause a Denial of Service. The weakness is catalogued as CWE-226 and CWE-770, indicating unchecked resource allocation and exposure of sensitive data before cleanup.

Affected Systems

The affected products are ASUS Business Manager and the ASUS System Control Interface suite, including the System Control Interface v3. The advisory does not list specific versions, so any installation of these components should be treated as vulnerable until a patch release specifies otherwise.

Risk and Exploitability

The issue has a CVSS score of 8.2, marking it high severity, but the EPSS score is less than 1 percent, indicating a very low probability of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is local; a user must possess administrator-level privileges to craft the IOCTL calls. Because the exploitation path is not publicly documented, an exact risk level cannot be precisely determined.

Generated by OpenCVE AI on August 1, 2026 at 09:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest ASUS security advisory update for the System Control Interface and Business Manager drivers.
  • Reboot the system after installing the update to ensure the patched drivers are loaded.
  • If an immediate patch cannot be applied, restrict access to the System Control Interface IOCTL interface so that only trusted administrators can invoke it, reducing the window for abuse.
  • Monitor system logs for abnormal IOCTL activity to detect potential attempts to exploit the flaw.

Generated by OpenCVE AI on August 1, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Administrator Can Exfiltrate Data and Cause DoS via Unchecked Resource Allocation in ASUS System Control Interface

Wed, 29 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Local Administrator Can Exfiltrate Data and Cause DoS via Unchecked Resource Allocation in ASUS System Control Interface

Sun, 26 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local Administrator IOCTL Resource Exhaustion and Information Disclosure in ASUS System Control Interface

Wed, 22 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Administrator IOCTL Resource Exhaustion and Information Disclosure in ASUS System Control Interface

Fri, 17 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Local Admin Can Leak Sensitive Data and Trigger DoS via Crafted IOCTL in ASUS System Control Interface

Thu, 16 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Admin Can Leak Sensitive Data and Trigger DoS via Crafted IOCTL in ASUS System Control Interface

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus business Manager
Asus system Control Interface
Asus system Control Interface V3
Weaknesses CWE-226
CWE-770
CPEs cpe:2.3:a:asus:business_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:system_control_interface:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:system_control_interface_v3:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus business Manager
Asus system Control Interface
Asus system Control Interface V3
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H'}


Subscriptions

Asus Business Manager System Control Interface System Control Interface V3
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-21T07:48:30.492Z

Reserved: 2026-06-29T00:35:42.676Z

Link: CVE-2026-13585

cve-icon Vulnrichment

Updated: 2026-07-21T07:48:30.492Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:15:03Z

Weaknesses
  • CWE-226

    Sensitive Information in Resource Not Removed Before Reuse

  • CWE-770

    Allocation of Resources Without Limits or Throttling