Impact
The operator can send a crafted IOCTL request to the Armoury Crate driver. Because the driver does not properly verify the caller, a local user can add an arbitrary process identifier to the driver’s whitelist. This allows the user to bypass the driver’s verification logic and potentially execute privileged operations that would otherwise be blocked. The weakness is captured by CWE‑782 standard. The impact is therefore local privilege escalation and possible abuse of privileged driver functions.
Affected Systems
The vulnerability affects ASUS Armoury Crate software, all product versions for which the Armoury Crate driver implements the exposed IOCTL. No specific version range was provided, so the risk applies to any installed Armoury Crate installation.
Risk and Exploitability
The CVSS score is 2, indicating low severity. EPSS is not available and the vulnerability is not listed in CISA KEV. The attack vector is local; a user with access to the system can craft the IOCTL request. Because the exploitation requires local interaction with the driver and no remote entry point, the practicality of exploitation is limited, but it can be used to elevate privileges on a compromised or compromised system.
OpenCVE Enrichment