Asus · Asus Business Manager · CVE-2026-13585
**Name of the Vulnerable Software and Affected Versions**
ASUS System Control Interface versions 3.0.x
ASUS Business Manager (affected versions not specified)
**Description**
The ASUS System Control Interface driver and ASUS Business Manager contain issues related to resource allocation without limits and sensitive information remaining in resources before reuse. Specifically, the `bsitf.sys` driver fails to validate IOCTL requests, allowing an attacker to map contiguous kernel memory to userspace and leak physical addresses. This can be exploited by a local administrator to disclose sensitive information or cause a system crash (Denial of Service) through pool exhaustion. The issue is linked to reference counter update errors in the IOCTL dispatch handler.
**Recommendations**
Update ASUS System Control Interface version 3.0.x to the latest security update provided by ASUS.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for ASUS Business Manager.