SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-8919

HIGH · CVSS 7.2 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

ASUS GameSDK is vulnerable due to a permissive cross-domain security policy that allows remote attackers to exploit untrusted domains. By tricking users into visiting a malicious webpage, an attacker can capture the user's NTLM hash, leading to potential information disclosure, data tampering, and access to other services. Organizations utilizing ASUS GameSDK should prioritize addressing this vulnerability to protect user credentials and maintain system integrity.

CVE
CVE-2026-8919
Severity
HIGH
CVSS
7.2
EPSS
0.30%

Original NVD Description

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK  ' section on the ASUS Security Advisory for more information.