AI analysis
CVE-2026-16006 is an information disclosure flaw (CWE-497) in the driver bundled with ASUS Armoury Crate, which fails to properly verify certain IOCTL requests. A local user with limited privileges can send a crafted IOCTL that bypasses the driver's verification checks and retrieve kernel virtual addresses. The disclosed addresses reveal the kernel memory layout, which is most valuable as a stepping stone in a chained attack, for example defeating kernel address-space randomization when exploiting a second bug. Any user of an ASUS system with the Armoury Crate driver installed (typically ROG/TUF gaming desktops, laptops and motherboards where Armoury Crate is bundled) is affected; the attack requires existing local code execution. There are no reports of in-the-wild exploitation, no public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.1% chance of exploitation in the next 30 days.
What to do: Update Armoury Crate to the patched build referenced in the 'Security Update for Armoury Crate App' section of the ASUS security advisory, using the Armoury Crate updater or the ASUS support site for your specific product; exact fixed version numbers were not included in the source data. Because exploitation requires local access and only leaks kernel addresses, risk is low on its own, but patch promptly since the leak can simplify chained exploits; on systems where Armoury Crate is not needed, uninstalling the software and its driver removes the exposure entirely.
Affected
| ASUS Armoury Crate (bundled driver) | — |
Estimated exposure
masslikely millions of installations (Armoury Crate is bundled/preinstalled on ASUS ROG and TUF gaming systems, and ASUS is the dominant motherboard vendor) — Estimated from ASUS's leading share of the gaming motherboard/PC market and the fact that Armoury Crate ships by default on ROG/TUF hardware, though only systems with the bundled driver loaded are affected and exploitation requires local…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.