ZeroHour

CVE-2026-16005

mass

Invalid Pointer Release in ASUS Armoury Crate Driver Lets Local Users Crash Systems

CVSS 4.0
5.8 medium
EPSS
<1%p0
Published
()
Modified
AI analysis

CVE-2026-16005 is an invalid pointer release flaw (CWE-763) in the driver bundled with ASUS Armoury Crate, ASUS's control software for its gaming hardware. A local, low-privileged user can trigger it by sending a crafted IOCTL request that bypasses the driver's verification, causing the driver to free arbitrary memory. The resulting corruption of data structures can crash the system with a blue screen (BSOD); the CVSS 4.0 vector indicates high integrity and availability impact with no confidentiality loss, and no network access or user interaction is required. Any machine with the Armoury Crate driver installed is affected, which broadly covers ASUS gaming motherboards, laptops and desktops. There is no evidence of exploitation in the wild, no public proof-of-concept, and the EPSS probability is low (0.1% over 30 days).

What to do: Update Armoury Crate to the fixed release published in the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory, using the in-app updater or ASUS support downloads (the source data does not state specific version numbers). Because exploitation requires local access and no exploits or PoCs are known, prioritize patching shared or multi-user Windows machines where untrusted local accounts exist. Note that the related headline about ASUS Control Center concerns a separate product and vulnerability and should not be conflated with this issue.

Affected
ASUS Armoury Crate (driver component)
Estimated exposure
massseveral million Windows installations (Armoury Crate ships by default on ASUS ROG/TUF gaming systems) — Armoury Crate is the default control software preinstalled on ASUS's ROG and TUF gaming motherboards, laptops and desktops, and ASUS ships tens of millions of such boards and systems annually, implying an installed base in the millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Weakness
CWE-763
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS patched CVE-2026-19397 (CVSS 7.7) in Control Center Express Agent, letting unauthenticated nearby attackers with an active session take over the host.

ASUS released version 1.7.24 of Control Center Express Agent to fix CVE-2026-19397, a CWE-306 missing-authentication flaw scored 7.7 on CVSS v4. Exploitation requires an active login session on the target and nearby network access, and agent compromise could lead to complete device takeover where the agent runs with elevated privileges. ASUS also issued a same-day advisory for Armory Crate covering ten additional CVEs.