Impact
A local user can bypass Armoury Crate driver authentication and allocate an unlimited amount of memory, exhausting system resources and causing the system to become unresponsive. The vulnerability is an instance of arbitrary resource allocation without limits (CWE-770), leading to a denial‑of‑service condition rather than unauthorized code execution or data disclosure.
Affected Systems
The vulnerability affects the ASUS Armoury Crate application, as identified by the CPE string for all versions of the product. No specific version information is provided, so all releases installed on a system are potentially impacted.
Risk and Exploitability
The CVSS score of 5.7 indicates a moderate severity that could impair availability for affected users. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting it is not a high‑profile exploit. The attack vector is likely local; a user who gains local access and can bypass driver authentication could trigger memory exhaustion by iteratively allocating memory until the system runs out of resources.
OpenCVE Enrichment