Description
Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the '
Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Published: 2026-09-08
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an exposed dangerous method or function in ASUS Armoury Crate that lets a local user bypass driver authentication and trigger system management interrupts. By repeatedly invoking the interrupt, a local attacker can cause brief system stalls and ultimately a denial‑of‑service. The weakness is categorized as CWE‑749.

Affected Systems

The vulnerability affects all installations of ASUS Armoury Crate running versions prior to the security fix detailed in the ASUS Security Advisory. No specific version numbers are listed, but any Armoury Crate instance that runs the affected application is impacted.

Risk and Exploitability

The CVSS score of 5.7 indicates medium severity for a local attacker. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, suggesting no known live exploits. Exploitation requires local access and involves sending malicious requests to the application, which then causes SMIs. Attackers can repeatedly trigger SMIs to stall the system until a reboot or patch prevents further stimulation. Because the exploit path is local, mitigation relies on applying the official security update or blocking the vulnerable functionality.

Generated by OpenCVE AI on September 8, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ASUS Armoury Crate to the latest version that includes the driver authentication bypass fix as described in the ASUS Security Advisory.
  • If an update cannot be applied immediately, disable the Armoury Crate application or its service so the dangerous method cannot be invoked.
  • Reduce local user privileges by removing administrative rights from users that do not require them, limiting their ability to trigger the vulnerable function.

Generated by OpenCVE AI on September 8, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 08 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Bypassed Driver Authentication in ASUS Armoury Crate

Tue, 08 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus armoury Crate
Weaknesses CWE-749
CPEs cpe:2.3:a:asus:armoury_crate:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus armoury Crate
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Armoury Crate
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-09-08T02:00:45.043Z

Reserved: 2026-08-18T09:44:04.634Z

Link: CVE-2026-75810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T03:17:18.880

Modified: 2026-09-08T03:17:18.880

Link: CVE-2026-75810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T03:30:17Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function