ZeroHour

CVE-2026-18023

mass

Local Information Disclosure in ASUS Armoury Crate Driver via Crafted IOCTL Requests

CVSS 4.0
5.7 medium
EPSS
<1%p0
Published
()
Modified
AI analysis

CVE-2026-18023 is an information disclosure flaw (CWE-226, Sensitive Information in Resource Not Removed Before Reuse) in the driver component of ASUS Armoury Crate, ASUS's tuning and control software bundled with its ROG/TUF gaming motherboards, laptops, and desktops. A local user with low privileges can send a specially crafted IOCTL request that bypasses the driver's security verification mechanism, causing the driver to return memory that has not been cleared of previously stored data. The attacker gains disclosure of sensitive information left in uninitialized memory, with high confidentiality impact but no integrity or availability impact per the CVSS 4.0 score of 5.7 (medium). Affected users are those running the Armoury Crate driver on ASUS systems; the vendor has published a fix in the 'Security Update for Armoury Crate App' section of its security advisory. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.1% probability of exploitation in the next 30 days.

What to do: Check which version of Armoury Crate and its driver is installed on affected ASUS systems and apply the update referenced in the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory, using the built-in Armoury Crate updater or the ASUS support download page. Because exploitation requires local access, prioritize shared or multi-user Windows machines; the ASUS advisory lists the specific fixed versions.

Affected
ASUS Armoury Crate (driver component)
Estimated exposure
massmillions of installations (Armoury Crate ships by default with ASUS ROG/TUF motherboards, gaming laptops, and desktops) — ASUS is the leading motherboard vendor and preinstalls Armoury Crate on its gaming hardware line, giving an installed base on the order of millions of systems, though the flaw only exposes local users of those machines.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Weakness
CWE-226
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS patched CVE-2026-19397 (CVSS 7.7) in Control Center Express Agent, letting unauthenticated nearby attackers with an active session take over the host.

ASUS released version 1.7.24 of Control Center Express Agent to fix CVE-2026-19397, a CWE-306 missing-authentication flaw scored 7.7 on CVSS v4. Exploitation requires an active login session on the target and nearby network access, and agent compromise could lead to complete device takeover where the agent runs with elevated privileges. ASUS also issued a same-day advisory for Armory Crate covering ten additional CVEs.