CVE-2026-13585 is a local, high-privilege vulnerability in the ASUS System Control Interface driver and ASUS Business Manager. Crafted IOCTL requests can invoke resource allocation handling that lacks effective size validation, input checking, allocation-count limits, and throttling. The issue is also associated with residual sensitive information in resources that are reused without being cleared. A local administrator can use the affected IOCTL path to disclose sensitive information; repeated uncontrolled allocations can exhaust kernel memory resources and destabilize the system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone Rust proof-of-concept repository for CVE-2026-13585 affecting ASUS bsitf.sys / AsusBSItf.sys on Windows. The repo contains a Cargo project with one executable source file (src/main.rs), a README with vulnerability analysis, and standard metadata files. The exploit is not framework-based. The main program opens the device \\.\bsitf using CreateFileA with read/write access, sends DeviceIoControl IOCTL 0x222808 with a caller-supplied allocation size, and expects a 16-byte structure containing a user-mode virtual address and physical address. It then dereferences the returned user VA directly, reads the first 16 bytes, writes 64 bytes of 0xCC, verifies readback, zeroes the test bytes, and finally calls IOCTL 0x22280C to free the mapping. This demonstrates that the driver maps kernel pool memory into the caller’s address space with read/write access. Exploit capability is local privilege escalation support in a BYOVD/admin-to-kernel context rather than remote compromise. The code itself does not hijack execution or gain SYSTEM automatically; instead it proves kernel-backed memory mapping, physical address disclosure, and controlled modification of the mapped buffer. Per the README, practical impacts include kernel pool exhaustion/DoS, physical address leakage, and on version 3.0.10.0 potentially executable kernel memory staging because allocations come from executable NonPagedPool. On 3.1.x, the pool is NonPagedPoolNx, reducing impact mainly to DoS and info leak unless chained with another vulnerability. Repository structure is minimal and purpose-built: Cargo.toml declares a Rust binary using the windows crate; src/main.rs implements device open, allocation, verification, and free routines; README.md documents affected versions, root cause, usage, and remediation. Overall this is a valid operational PoC for a local Windows kernel-driver vulnerability, not merely a detector or README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity flaw in ASUS driver components involving missing resource throttling and residual data exposure before reuse, leading to sensitive information disclosure and possible denial of service.
A vulnerability in the ASUS bsitf.sys driver that allows arbitrary physical memory mapping through an unvalidated IOCTL, implying a dangerous kernel-level security flaw.
An arbitrary physical memory mapping vulnerability in the ASUS bsitf.sys / AsusBSItf.sys kernel driver shipped with ASUS Business Manager and Software Manager.
An improper access control vulnerability in specific driver components of ASUS System Control Interface and/or ASUS Business Manager that could allow a local administrator to bypass intended security restrictions and impact system integrity.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.