Impact
The flaw is an exposed dangerous method or function in ASUS Armoury Crate that lets a local user bypass driver authentication and trigger system management interrupts. By repeatedly invoking the interrupt, a local attacker can cause brief system stalls and ultimately a denial‑of‑service. The weakness is categorized as CWE‑749.
Affected Systems
The vulnerability affects all installations of ASUS Armoury Crate running versions prior to the security fix detailed in the ASUS Security Advisory. No specific version numbers are listed, but any Armoury Crate instance that runs the affected application is impacted.
Risk and Exploitability
The CVSS score of 5.7 indicates medium severity for a local attacker. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, suggesting no known live exploits. Exploitation requires local access and involves sending malicious requests to the application, which then causes SMIs. Attackers can repeatedly trigger SMIs to stall the system until a reboot or patch prevents further stimulation. Because the exploit path is local, mitigation relies on applying the official security update or blocking the vulnerable functionality.
OpenCVE Enrichment