ZeroHour

CVE-2026-16003

mass

Exposed IOCTL in ASUS Armoury Crate driver allows local whitelist bypass

CVSS 4.0
2.0 low
EPSS
<1%p0
Published
()
Modified
AI analysis

ASUS Armoury Crate's bundled driver exposes an IOCTL interface with insufficient access control (CWE-782), letting a local user bypass the driver's verification and add an arbitrary process identifier to the driver's whitelist. An attacker with low privileges on the machine can trigger this by sending a crafted IOCTL request, gaining limited integrity impact by getting a process of their choice treated as trusted by the driver. The flaw is rated Low (CVSS 4.0 score 2.0) because it requires local access, involves high attack complexity, and has a low-only integrity impact, and it affects systems running the Armoury Crate driver that ASUS bundles with its motherboards and gaming products. No public proofs of concept are known, the issue is not on the CISA KEV list, and EPSS currently estimates only a 0.1% probability of exploitation in the next 30 days. ASUS has addressed it via the 'Security Update for Armoury Crate App' section of its security advisory, though specific affected or fixed version numbers were not provided in the available data.

What to do: Update Armoury Crate using the app's built-in updater or the package referenced in the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory, and check your installed version against that advisory since no version numbers are given here. Because exploitation requires local low-privileged code execution, avoid running untrusted local processes on affected systems until patched. No workaround is documented in the available data.

Affected
ASUS Armoury Crate (bundled driver component)
Estimated exposure
massmillions of ASUS systems with the Armoury Crate driver installed — Armoury Crate ships preinstalled with ASUS motherboards and ROG gaming hardware and ASUS is the world's largest motherboard vendor, making the installed base plausibly in the millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Weakness
CWE-782
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS patched CVE-2026-19397 (CVSS 7.7) in Control Center Express Agent, letting unauthenticated nearby attackers with an active session take over the host.

ASUS released version 1.7.24 of Control Center Express Agent to fix CVE-2026-19397, a CWE-306 missing-authentication flaw scored 7.7 on CVSS v4. Exploitation requires an active login session on the target and nearby network access, and agent compromise could lead to complete device takeover where the agent runs with elevated privileges. ASUS also issued a same-day advisory for Armory Crate covering ten additional CVEs.