Description
Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement.
Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.
Published: 2026-07-30
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in ASUS Armoury Crate allows a local user to replace a protected file with a crafted version and then execute arbitrary code with elevated privileges. The flaw, identified as CWE‑362, can give the attacker system control or the ability to run malicious processes under higher privileges. The impact is strictly local, affecting only users who can write to the directories involved.

Affected Systems

The vulnerability affects ASUS Armoury Crate. No specific version numbers appear in the advisory, so all installed copies of Armoury Crate may be vulnerable until an update that fixes the race condition is released.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, but the EPSS score of less than 1% suggests a low current exploitation probability. The issue is not listed in CISA KEV, reinforcing that it is not a known, widely exploited vulnerability. Based on the description, it is inferred that an attacker needs local access to the system and write permissions on the Armoury Crate directories to perform the crafted file replacement and trigger the race condition.

Generated by OpenCVE AI on August 4, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official ASUS Armoury Crate security update that addresses the race condition.
  • Limit write permissions on Armoury Crate installation and configuration directories so that only trusted administrators can modify them.
  • Disable or monitor any automated processes or scheduled tasks that could write to the protected Armoury Crate files and restore any altered files to their original state after updates.

Generated by OpenCVE AI on August 4, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 04 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Armoury Crate Race Condition Enables Local Privilege Escalation

Sun, 02 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Armoury Crate Race Condition Enables Local Privilege Escalation

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Description Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus armoury Crate
Weaknesses CWE-362
CPEs cpe:2.3:a:asus:armoury_crate:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus armoury Crate
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Armoury Crate
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-07-31T03:55:49.349Z

Reserved: 2026-07-23T03:32:02.585Z

Link: CVE-2026-16727

cve-icon Vulnrichment

Updated: 2026-07-30T13:14:11.297Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T02:16:45.537

Modified: 2026-07-31T04:16:48.200

Link: CVE-2026-16727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:00:15Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')