Exposed Dangerous Method in ASUS Armoury Crate Enables Local DoS via SMI Triggering
AI analysis
CVE-2026-75810 is an exposed dangerous method or function (CWE-749) in ASUS Armoury Crate that leaves a driver interface used to trigger system management interrupts (SMIs) accessible without proper authentication. A local user with limited privileges can bypass the driver's authentication and send requests that invoke the SMI path, causing a brief system stall; repeatedly triggering SMIs can escalate into a denial-of-service condition. The impact is availability-only: the CVSS 4.0 vector shows high availability impact with no confidentiality or integrity impact, and the high attack complexity means triggering is not reliably repeatable on every attempt. Any ASUS system with the Armoury Crate app and its driver components installed is potentially affected, but the affected version ranges are not specified in the available data, so defenders should consult the 'Security Update for Armoury Crate App' section of the ASUS advisory. There is no evidence of exploitation so far: the issue is not in CISA KEV, EPSS estimates only a 0.1% probability of exploitation in the next 30 days, and no public proof-of-concept is known.
What to do: Install the Armoury Crate fix referenced in the ASUS advisory's 'Security Update for Armoury Crate App' section (via the Armoury Crate update center or ASUS support downloads) and verify the installed version afterwards, since exact affected and fixed version numbers are not given in the available data. Because exploitation requires local access and affects availability only, prioritizing shared or multi-user ASUS systems is sufficient; note that the related ASUS Control Center unauthenticated-root headline concerns a different product and should be tracked separately.
Affected
| ASUS Armoury Crate (app and driver components) | — |
Estimated exposure
massplausibly millions of ASUS gaming desktop, laptop, and motherboard installations with Armoury Crate present — Armoury Crate is bundled/preinstalled software on ASUS ROG and TUF gaming motherboards, laptops, and desktops, and ASUS's position as one of the largest motherboard and gaming-PC vendors implies an installed base well above one million,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.