Impact
The Armoury Crate driver contains a flaw that allows a local user to issue a crafted IOCTL request that frees an arbitrary memory pointer. This bypasses the driver’s validation logic, corrupts internal data structures, and can lead to a system crash (BSOD). The vulnerability represents a classic example of freeing an invalid pointer (CWE‑763) and may enable a local user to disrupt system operation or potentially leverage corrupted memory for further malicious actions.
Affected Systems
The vulnerability impacts the ASUS Armoury Crate software. No specific product versions are enumerated in the advisory, so all released versions containing the driver may be susceptible.
Risk and Exploitability
With a CVSS score of 5.8 the vulnerability is considered moderate. The attack vector is local, requiring user‑level access to craft the IOCTL request. The EPSS score is currently unavailable, and the issue is not listed in CISA’s KEV catalog. No publicly available exploits have been reported, but the potential for denial of service makes timely remediation advisable.
OpenCVE Enrichment