ASUS GameSDK Permissive Cross-Domain Security Policy Vulnerability Allowing NTLM Hash Theft

Vulnerability

A vulnerability in ASUS GameSDK, present in versions through 1.0.5, allows remote users to steal local users' NTLM hashes. This is achieved by persuading users to visit a malicious webpage that triggers a request containing a UNC path to the application's local service endpoint. The vulnerability could lead to unauthorized information disclosure, data tampering, and potential disruption of the GameSDK application, as well as unauthorized access to the victim's information on other services.

Impact

Exploitation of this vulnerability could result in unauthorized access to NTLM hashes, allowing for potential pass-the-hash attacks, and could disrupt the availability of the GameSDK application.

Remediation

Users are advised to update to ASUS GameSDK version 1.0.6 or later.

Added: Jul 15, 2026, 3:26 AM
Updated: Jul 15, 2026, 3:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.6
exploitability
5.8
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.