Description
Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism.
Refer to the '
Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Published: 2026-09-08
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A resource within the ASUS Armoury Crate driver is not cleared before it is reused; the driver allows a local user to send a crafted IOCTL request that bypasses its security verification, enabling that same user to read uninitialized memory and extract sensitive information that was previously stored in the kernel space.

Affected Systems

All current releases of the Armoury Crate driver distributed by ASUS are affected, as the vulnerability exists in every version that has not yet been updated with the security fix. The fault occurs in the driver handling IOCTLs on systems that run Armoury Crate.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity. The exploitability requires the attacker to have local access on the machine and to craft a specific IOCTL packet. Because local users can trigger the flaw, the risk is confined to the device owner or other local accounts; no remote exploitation is described. The EKV table does not list this vulnerability, and the EPSS score is not available, implying that publicly known exploitation is not confirmed yet.

Generated by OpenCVE AI on September 8, 2026 at 03:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Armoury Crate update or driver release issued by ASUS, which cleans the resource before reuse.
  • Revoke write access to the Armoury Crate device node so that only trusted accounts can issue IOCTL requests.
  • Monitor system logs for anomalous IOCTL activity and disable the Armoury Crate driver if the functionality is not required to reduce exposure.

Generated by OpenCVE AI on September 8, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 08 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Local user can read uninitialized memory via crafted IOCTL in ASUS Armoury Crate

Tue, 08 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus armoury Crate
Weaknesses CWE-226
CPEs cpe:2.3:a:asus:armoury_crate:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus armoury Crate
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Asus Armoury Crate
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-09-08T02:03:38.922Z

Reserved: 2026-07-28T00:59:26.211Z

Link: CVE-2026-18023

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T03:17:18.050

Modified: 2026-09-08T03:17:18.050

Link: CVE-2026-18023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T03:30:17Z

Weaknesses
  • CWE-226

    Sensitive Information in Resource Not Removed Before Reuse