Invalid Pointer Release in ASUS Armoury Crate Driver Lets Local Users Crash Systems
AI analysis
CVE-2026-16005 is an invalid pointer release flaw (CWE-763) in the driver bundled with ASUS Armoury Crate, ASUS's control software for its gaming hardware. A local, low-privileged user can trigger it by sending a crafted IOCTL request that bypasses the driver's verification, causing the driver to free arbitrary memory. The resulting corruption of data structures can crash the system with a blue screen (BSOD); the CVSS 4.0 vector indicates high integrity and availability impact with no confidentiality loss, and no network access or user interaction is required. Any machine with the Armoury Crate driver installed is affected, which broadly covers ASUS gaming motherboards, laptops and desktops. There is no evidence of exploitation in the wild, no public proof-of-concept, and the EPSS probability is low (0.1% over 30 days).
What to do: Update Armoury Crate to the fixed release published in the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory, using the in-app updater or ASUS support downloads (the source data does not state specific version numbers). Because exploitation requires local access and no exploits or PoCs are known, prioritize patching shared or multi-user Windows machines where untrusted local accounts exist. Note that the related headline about ASUS Control Center concerns a separate product and vulnerability and should not be conflated with this issue.
Affected
| ASUS Armoury Crate (driver component) | — |
Estimated exposure
massseveral million Windows installations (Armoury Crate ships by default on ASUS ROG/TUF gaming systems) — Armoury Crate is the default control software preinstalled on ASUS's ROG and TUF gaming motherboards, laptops and desktops, and ASUS ships tens of millions of such boards and systems annually, implying an installed base in the millions.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.