Impact
A race condition in ASUS Armoury Crate allows a local user to replace a protected file with a crafted version and then execute arbitrary code with elevated privileges. The flaw, identified as CWE‑362, can give the attacker system control or the ability to run malicious processes under higher privileges. The impact is strictly local, affecting only users who can write to the directories involved.
Affected Systems
The vulnerability affects ASUS Armoury Crate. No specific version numbers appear in the advisory, so all installed copies of Armoury Crate may be vulnerable until an update that fixes the race condition is released.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, but the EPSS score of less than 1% suggests a low current exploitation probability. The issue is not listed in CISA KEV, reinforcing that it is not a known, widely exploited vulnerability. Based on the description, it is inferred that an attacker needs local access to the system and write permissions on the Armoury Crate directories to perform the crafted file replacement and trigger the race condition.
OpenCVE Enrichment