CVE-2026-13585

HIGH

Asus System Control Interface v3 - Sensitive Information in Resource Not Removed Before Reuse

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-13585. PoCs published by 416rehman.

AI-analyzed exploit summary This PoC demonstrates a kernel memory mapping vulnerability in ASUS bsitf.sys/AsusBSItf.sys drivers via IOCTL 0x222808, allowing usermode read/write access to allocated kernel memory. The exploit confirms the ability to write and verify data in kernel space, though it requires administrator privileges to open the device.

Description

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the '  Security Update for ASUS System Control Interface  ' section on the ASUS Security Advisory for more information.

Exploits (1)

github WORKING POC 3 stars
by 416rehman · rustpoc
https://github.com/416rehman/asus-bsitf-0-day-poc

This PoC demonstrates a kernel memory mapping vulnerability in ASUS bsitf.sys/AsusBSItf.sys drivers via IOCTL 0x222808, allowing usermode read/write access to allocated kernel memory. The exploit confirms the ability to write and verify data in kernel space, though it requires administrator privileges to open the device.

Classification
Working Poc 99%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: ASUS bsitf.sys v3.0.10.0, AsusBSItf.sys v3.1.10.0/v3.1.25.0
Auth required
Prerequisites: Administrator privileges to open the device handle · Vulnerable ASUS driver loaded on the system
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

Scores

CVSS v4 8.2
EPSS 0.0031
EPSS Percentile 23.0%
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-226 CWE-770
Status published
Products (3)
ASUS/Business Manager < v3.0.38.0
ASUS/System Control Interface < v1.1.40.0
ASUS/System Control Interface v3 < v3.1.66.0
Published Jul 15, 2026
Tracked Since Jul 15, 2026