Impact
A resource within the ASUS Armoury Crate driver is not cleared before it is reused; the driver allows a local user to send a crafted IOCTL request that bypasses its security verification, enabling that same user to read uninitialized memory and extract sensitive information that was previously stored in the kernel space.
Affected Systems
All current releases of the Armoury Crate driver distributed by ASUS are affected, as the vulnerability exists in every version that has not yet been updated with the security fix. The fault occurs in the driver handling IOCTLs on systems that run Armoury Crate.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity. The exploitability requires the attacker to have local access on the machine and to craft a specific IOCTL packet. Because local users can trigger the flaw, the risk is confined to the device owner or other local accounts; no remote exploitation is described. The EKV table does not list this vulnerability, and the EPSS score is not available, implying that publicly known exploitation is not confirmed yet.
OpenCVE Enrichment