Search/CVE-2026-13585
CVE

CVE-2026-13585

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.

CVSS v3.1
EPSS
0.16%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 26, 2026
0.14pp
0.31% → 0.16% over 2 tracked changes
Connections
2 relationships
Timeline
disclosure → media coverage
Jul 15, 2026
Disclosure — published as a CVE record. · last revised by NVD Sep 17, 2026
Public PoC (1)
Unverified third-party code — review before executing.