Impact
An exposed IOCTL interface in the Armoury Crate driver has insufficient access control, allowing a local user to issue crafted IOCTL calls that read and write arbitrary PCI/PCIe configuration space. This can let a local attacker gain elevated privileges or disrupt hardware configuration, potentially compromising entire system integrity.
Affected Systems
The vulnerability affects the Armoury Crate driver distributed with ASUS systems. Specific version information is not provided in the advisory, so any installation of the driver that is still unpatched may be impacted. The flaw is categorized under CWE-782, indicating insufficient authorization controls.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires local user context and crafted IOCTL requests, an attacker must first gain legitimate local access to the system. Once local access is achieved, the flaw can be leveraged to alter PCI configuration, potentially facilitating privilege escalation or denial of service of connected devices.
OpenCVE Enrichment