ZeroHour

CVE-2026-12962

mass

Cross-Domain NTLM Hash Leak in ASUS Armoury Crate Local Service

CVSS 4.0
5.3 medium
EPSS
<1%p29
Published
()
Modified
AI analysis

ASUS Armoury Crate, the bundled management software shipped with ASUS ROG/TUF motherboards, laptops and desktops, runs a local service whose endpoint accepts requests from untrusted web origins due to a permissive cross-domain security policy (CWE-942). An attacker triggers the flaw by convincing a logged-in Windows user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint, causing the system to authenticate to a resource of the attacker's choosing. The attacker obtains the local user's NTLM hash, which can be cracked offline or relayed to other services that accept NTLM authentication. Any Windows user running Armoury Crate on an ASUS system is affected; exploitation requires user interaction and results in credential disclosure rather than code execution. No public proof of concept is known, the flaw is not in CISA's KEV catalog, EPSS assigns a 0.4% probability of exploitation in the next 30 days, and ASUS scores it medium severity (CVSS 4.0: 5.3), so no active exploitation is currently known.

What to do: Apply the Armoury Crate update referenced in the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory, using the Armoury Crate update/installer tool to confirm the installed version. As interim mitigations, block outbound SMB/UNC authentication to untrusted hosts and restrict NTLM usage via group policy or Windows firewall rules. Inventory Windows endpoints with Armoury Crate installed and prioritize systems where users browse the web under privileged credentials, since leaked NTLM hashes can be cracked or relayed.

Affected
ASUS Armoury Crate
Estimated exposure
massmillions of Windows systems (Armoury Crate is preinstalled across ASUS motherboards, laptops and desktops) — Armoury Crate ships by default with ASUS ROG/TUF motherboards, gaming laptops and desktops, and ASUS's leading motherboard market share makes the installed base plausibly in the millions, though only systems with the local service enabled…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Weakness
CWE-942
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS patched CVE-2026-19397 (CVSS 7.7) in Control Center Express Agent, letting unauthenticated nearby attackers with an active session take over the host.

ASUS released version 1.7.24 of Control Center Express Agent to fix CVE-2026-19397, a CWE-306 missing-authentication flaw scored 7.7 on CVSS v4. Exploitation requires an active login session on the target and nearby network access, and agent compromise could lead to complete device takeover where the agent runs with elevated privileges. ASUS also issued a same-day advisory for Armory Crate covering ten additional CVEs.