PT-2026-58876 · Asus · Gamesdk

CVE-2026-8919

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ASUS GameSDK (affected versions not specified)
Description A permissive Cross-domain Security Policy with untrusted domains allows a remote user to obtain a local user’s NTLM hash. This occurs when a user is convinced to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This issue can lead to information disclosure, data tampering, service unavailability for GameSDK, or unauthorized access to the victim’s information on other services.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8919

Affected Products

Gamesdk