CVE-2026-8919 Details
Description
Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK ' section on the ASUS Security Advisory for more information.
A vulnerability in ASUS GameSDK, present in versions through 1.0.5, allows remote users to steal local users' NTLM hashes. This is achieved by persuading users to visit a malicious webpage that triggers a request containing a UNC path to the application's local service endpoint. The vulnerability could lead to unauthorized information disclosure, data tampering, and potential disruption of the GameSDK application, as well as unauthorized access to the victim's information on other services.
Users are advised to update to ASUS GameSDK version 1.0.6 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asus.com/security-advisory/ | ASUS | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-942 | Permissive Cross-domain Policy with Untrusted Domains | ASUS |
Affected Products
| Product | Versions |
|---|---|
| ASUS GameSDK | <= 1.0.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | ASUS |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | ASUS |
Volerion