CVE-2026-8919
HIGHAsus GameSDK < V1.0.5 - Permissive Cross-domain Security Policy with Untrusted Domains
Title source: ruleDescription
Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK ' section on the ASUS Security Advisory for more information.
References (1)
Core 1
Core References
Scores
CVSS v4
7.2
EPSS
0.0030
EPSS Percentile
22.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-942
Status
published
Products (1)
ASUS/GameSDK
< V1.0.5
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026