Impact
The ASUS Armoury Crate application contains a flaw that allows a user with local access to bypass driver authentication and write to critical hardware registers. This vulnerability is classified as Improper Restriction of Software Interfaces to Hardware Features, identified as CWE-1256. A local attacker could therefore alter on‑board configuration settings in a way that may physically damage the system or cause it to behave unpredictably.
Affected Systems
The advisory references the Armoury Crate application for ASUS devices. Specific version information is not provided, so any device running an unpatched version of Armoury Crate may be affected. The impact applies to the hardware configuration functionality exposed through the application.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate risk. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Because the flaw requires local user privileges, exploitation is limited to anyone who can log into the machine and launch Armoury Crate. The attack path involves launching the application, modifying protected settings, and writing to model‑specific registers without proper authorization. The absence of a remote entry point reduces the likelihood of widespread exploitation but still poses a significant risk to systems with exposed hardware configuration tools.
OpenCVE Enrichment