Description
Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the '
Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Published: 2026-09-08
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ASUS Armoury Crate application contains a flaw that allows a user with local access to bypass driver authentication and write to critical hardware registers. This vulnerability is classified as Improper Restriction of Software Interfaces to Hardware Features, identified as CWE-1256. A local attacker could therefore alter on‑board configuration settings in a way that may physically damage the system or cause it to behave unpredictably.

Affected Systems

The advisory references the Armoury Crate application for ASUS devices. Specific version information is not provided, so any device running an unpatched version of Armoury Crate may be affected. The impact applies to the hardware configuration functionality exposed through the application.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate risk. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Because the flaw requires local user privileges, exploitation is limited to anyone who can log into the machine and launch Armoury Crate. The attack path involves launching the application, modifying protected settings, and writing to model‑specific registers without proper authorization. The absence of a remote entry point reduces the likelihood of widespread exploitation but still poses a significant risk to systems with exposed hardware configuration tools.

Generated by OpenCVE AI on September 8, 2026 at 03:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Armoury Crate update from ASUS, which restores proper driver authentication and restricts register access.
  • If the device does not require hardware configuration via Armoury Crate, uninstall the application or limit local user access.
  • Restrict local user privileges and enforce least privilege for Armoury Crate usage.

Generated by OpenCVE AI on September 8, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 08 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus armoury Crate
Weaknesses CWE-1256
CPEs cpe:2.3:a:asus:armoury_crate:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus armoury Crate
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asus Armoury Crate
cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-09-08T02:00:06.560Z

Reserved: 2026-08-18T09:44:05.831Z

Link: CVE-2026-75811

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T03:17:19.007

Modified: 2026-09-08T03:17:19.007

Link: CVE-2026-75811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T03:30:17Z

Weaknesses
  • CWE-1256

    Improper Restriction of Software Interfaces to Hardware Features