Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services.
Refer to the ' Security Update for ASUS GameSDK ' section on the ASUS Security Advisory for more information.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.asus.com/security-advisory/ |
Configurations
No configuration.
History
15 Jul 2026, 02:22
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 02:22
Updated : 2026-07-15 16:24
NVD link : CVE-2026-8919
Mitre link : CVE-2026-8919
CVE.ORG link : CVE-2026-8919
JSON object : View
Products Affected
No product.
CWE
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
