ZeroHour

CVE-2026-75808

mass

Local DoS via Unrestricted Memory Allocation in ASUS Armoury Crate

CVSS 4.0
5.7 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-75808 is a resource-allocation flaw (CWE-770) in ASUS Armoury Crate in which the software allocates system memory without limits or throttling. A local user can trigger it by bypassing driver authentication and then allocating an unrestricted amount of memory, exhausting system memory and causing a denial-of-service condition. Per the CVSS 4.0 vector (AV:L/AC:H/PR:L/VA:H), the attack requires local access with low privileges, carries high attack complexity, and impacts availability only — the attacker gains a system crash or DoS, not data exposure or privilege escalation. All users with ASUS Armoury Crate installed on ASUS systems (gaming motherboards, laptops, and desktops where it ships as bundled companion software) are potentially affected. Exploitation is currently unknown: no public proof-of-concept exists, EPSS is 0.1% (1st percentile), the flaw is not in CISA KEV, and no fixed version numbers are listed in the source data.

What to do: Check the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory and install the fixed Armoury Crate release it lists (e.g., via Armoury Crate Live Update or the ASUS support download page), since exact fixed version numbers are not provided in the source data. Until patched, restrict local access to untrusted or low-privileged users on systems running Armoury Crate. Given the local-only, availability-impacting nature and very low EPSS, urgency is moderate — treat as routine patching.

Affected
ASUS Armoury Crate (Armoury Crate App and its associated driver component)
Estimated exposure
masslikely millions of users (Armoury Crate ships preinstalled/bundled across ASUS ROG and TUF hardware) — Armoury Crate is the default companion utility ASUS installs on its ROG/TUF gaming motherboards, laptops, and desktops, and ASUS is one of the world's largest motherboard and gaming-PC vendors, so the installed base plausibly runs into the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Weakness
CWE-770
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ASUS Control Center Critical Flaw Allows Unauthenticated Attackers to Gain Root Access

ASUS patched CVE-2026-19397 (CVSS 7.7) in Control Center Express Agent, letting unauthenticated nearby attackers with an active session take over the host.

ASUS released version 1.7.24 of Control Center Express Agent to fix CVE-2026-19397, a CWE-306 missing-authentication flaw scored 7.7 on CVSS v4. Exploitation requires an active login session on the target and nearby network access, and agent compromise could lead to complete device takeover where the agent runs with elevated privileges. ASUS also issued a same-day advisory for Armory Crate covering ten additional CVEs.