What is CVE-2026-13585?
The CVE-2026-13585 vulnerability in the ASUS bsitf.sys driver allows arbitrary physical memory mapping via an unvalidated IOCTL request. This can enable a local attacker to gain read/write access to system memory, potentially leading to privilege escalation. Users are advised to apply the security update provided by ASUS.
Azərbaycanca: ASUS-un bsitf.sys sürücüsündə aşkar edilmiş CVE-2026-13585 zəifliyi, təsdiqlənməmiş IOCTL sorğusu vasitəsilə ixtiyari fiziki yaddaş xəritələnməsinə imkan verir. Bu, yerli təcavüzkara sistem yaddaşına birbaşa oxuma/yazma imkanı yaradaraq imtiyazların yüksəldilməsinə səbəb ola bilər. İstifadəçilərə ASUS tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmələri tövsiyə olunur.
FAQ2
In which ASUS file does the CVE-2026-13585 vulnerability exist?
This vulnerability resides in the ASUS bsitf.sys driver.
What does CVE-2026-13585 allow a local attacker to do?
This vulnerability can enable a local attacker to gain read/write access to system memory, potentially leading to privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.