CVE-2026-13585
HIGHAsus System Control Interface v3 - Sensitive Information in Resource Not Removed Before Reuse
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-13585. PoCs published by 416rehman.
AI-analyzed exploit summary This PoC demonstrates a kernel memory mapping vulnerability in ASUS bsitf.sys/AsusBSItf.sys drivers via IOCTL 0x222808, allowing usermode read/write access to allocated kernel memory. The exploit confirms the ability to write and verify data in kernel space, though it requires administrator privileges to open the device.
Description
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.
Exploits (1)
This PoC demonstrates a kernel memory mapping vulnerability in ASUS bsitf.sys/AsusBSItf.sys drivers via IOCTL 0x222808, allowing usermode read/write access to allocated kernel memory. The exploit confirms the ability to write and verify data in kernel space, though it requires administrator privileges to open the device.
References (2)
Scores
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X