ASUS disclosed CVE-2026-13585, a high-severity flaw affecting ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager. The vulnerability stems from improper handling of driver resources, including allocation without limits and failure to clear sensitive data before reuse, allowing a local administrator to use crafted IOCTL requests to disclose sensitive information. In severe cases, the issue can also trigger a denial of service on the affected host, according to the CVE record and ASUS advisory.
Public discussion identified the affected kernel driver as bsitf.sys / AsusBSItf.sys and described the bug as an arbitrary physical memory mapping issue tied to unvalidated IOCTL handling. Posts circulating in security and administrator forums said a technical write-up and proof of concept had been published, increasing visibility into the flaw and its potential abuse as a local kernel-level security risk on ASUS business systems. ASUS has published remediation guidance and countermeasures for impacted products.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Reddit posts drew attention to CVE-2026-13585 as an ASUS bsitf.sys / AsusBSItf.sys issue described as arbitrary physical memory mapping via an unvalidated IOCTL. One post said a full technical analysis and proof of concept by Ahmad Zahran was available and that ASUS had released a vendor advisory with countermeasures.
A new vulnerability, CVE-2026-13585, was published affecting ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager. The flaw can allow sensitive information disclosure via crafted IOCTL requests and, in severe cases, denial of service; the CVE record also references an ASUS security advisory.
A blog post by Ahmad Zahran published a technical analysis and proof of concept for the ASUS bsitf.sys issue described as arbitrary physical memory mapping. This constitutes public release of exploit details for the vulnerability later tracked as CVE-2026-13585.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcereddit.com
Open sourcecvefeed.io
Open sourcecve.org
Open sourceblog.ahmadz.ai
Open sourceseclists.org
Open sourceasus.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.