Description
Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the '
Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.
Published: 2026-09-08
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (system crash)
Action: Apply patch
AI Analysis

Impact

The Armoury Crate driver contains a flaw that allows a local user to issue a crafted IOCTL request that frees an arbitrary memory pointer. This bypasses the driver’s validation logic, corrupts internal data structures, and can lead to a system crash (BSOD). The vulnerability represents a classic example of freeing an invalid pointer (CWE‑763) and may enable a local user to disrupt system operation or potentially leverage corrupted memory for further malicious actions.

Affected Systems

The vulnerability impacts the ASUS Armoury Crate software. No specific product versions are enumerated in the advisory, so all released versions containing the driver may be susceptible.

Risk and Exploitability

With a CVSS score of 5.8 the vulnerability is considered moderate. The attack vector is local, requiring user‑level access to craft the IOCTL request. The EPSS score is currently unavailable, and the issue is not listed in CISA’s KEV catalog. No publicly available exploits have been reported, but the potential for denial of service makes timely remediation advisable.

Generated by OpenCVE AI on September 8, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Armoury Crate to the latest version following the ASUS Security Advisory.
  • If an update is not available, disable or uninstall the Armoury Crate application to eliminate the threat surface.
  • After remediation, monitor system stability and review logs for BSODs or other evidence of memory corruption.

Generated by OpenCVE AI on September 8, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 17 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:asus:armoury_crate:*:*:*:*:*:*:*:* cpe:2.3:a:asus:armoury_crate:through_6.5.7:*:*:*:*:*:*:*

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via crafted IOCTL in Armoury Crate driver

Tue, 08 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus armoury Crate
Weaknesses CWE-763
CPEs cpe:2.3:a:asus:armoury_crate:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus armoury Crate
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Armoury Crate
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-09-17T08:45:35.235Z

Reserved: 2026-07-17T03:32:51.198Z

Link: CVE-2026-16005

cve-icon Vulnrichment

Updated: 2026-09-08T14:23:10.154Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T03:17:17.797

Modified: 2026-09-17T09:16:39.767

Link: CVE-2026-16005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T05:30:09Z

Weaknesses
  • CWE-763

    Release of Invalid Pointer or Reference