AI analysis
ASUS Armoury Crate contains an improper restriction of software interfaces to hardware features (CWE-1256), allowing a local user to bypass driver authentication and directly access critical model-specific registers. The flaw is triggered locally by a low-privileged user without user interaction, though with high attack complexity (CVSS v4.0 5.8: AV:L/AC:H/PR:L/UI:N). A successful exploit lets the attacker modify hardware configuration settings and potentially cause hardware damage, yielding high integrity and availability impact. Any user running the ASUS Armoury Crate utility on ASUS systems is affected; affected and fixed versions are specified in the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory. No public proof of concept, no CISA KEV listing, and a low EPSS of 0.1% mean exploitation is not currently known, and the separately reported ASUS Control Center root-access flaw is a distinct issue.
What to do: Apply the Armoury Crate update referenced in the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory (the source data does not specify a fixed version number). Because exploitation requires local access, limit which local accounts are used on ASUS systems running the tool. Open Armoury Crate and verify the app is running the latest release via its updater.
Estimated exposure
massseveral million installations (Armoury Crate is bundled with ASUS motherboards, gaming laptops and desktops) — Armoury Crate ships with most recent ASUS motherboards, laptops and desktops and ASUS is the leading motherboard vendor, so the install base plausibly runs to millions of systems, though only local users on those machines can exploit the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.