Executive brief
The Armoury Crate driver on ASUS systems contains a flaw that allows local users to read and write arbitrary PCI/PCIe configuration space without proper authorization checks. This could allow a local attacker to modify hardware settings or extract sensitive information, potentially compromising system stability or enabling further attacks.
Technical details
The vulnerability is an insufficient access control issue in an IOCTL handler within the ASUS Armoury Crate driver. An attacker with local system access can craft malicious IOCTL requests that bypass the driver's verification mechanisms to directly read and write PCI/PCIe configuration space. This requires local code execution privileges but no authentication. The flaw allows unauthorized hardware-level configuration access, which could be leveraged for privilege escalation, hardware tampering, or information disclosure. A security update is available via the ASUS Security Advisory.
Affected products
- ASUS Armoury Crate
Timeline
- 2026-09-08: disclosed