Impact
The vulnerability is a permissive cross-domain security policy that allows untrusted domains to send UNC paths to the Armoury Crate local service endpoint. By tricking a user into viewing a crafted web page that includes such a request, an attacker can obtain the local user's NTLM hash, leading to a moderate confidentiality compromise via credential theft. The weakness corresponds to CWE‑942.
Affected Systems
Affected systems are devices running ASUS Armoury Crate software. The advisory does not list specific versions, so all current releases of Armoury Crate should be considered potentially vulnerable until patched.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the precise exploitation probability is uncertain; the KEV catalog does not list this vulnerability, suggesting no widespread known exploitation. The attack vector is remote: a malicious web page can induce a local user to send a UNC request to the local service, allowing the attacker to capture the NTLM hash. While public exploits are not known, the sensitive credential leakage warrants timely remediation.
OpenCVE Enrichment