Executive brief
The ASUS Armoury Crate driver contains a memory management vulnerability that allows a local attacker with limited privileges to crash the system or corrupt memory through a specially crafted driver command. This could lead to data loss, system instability, or provide a stepping stone for further attacks on affected ASUS computers.
Technical details
The Armoury Crate driver is vulnerable to a use-after-free (release of invalid pointer) condition in its IOCTL request handling. An attacker can bypass the driver's input verification and supply a crafted IOCTL request that causes the driver to free an arbitrary memory address, leading to memory corruption and triggering a blue screen of death (BSOD). The vulnerability requires local access to the system but does not require elevated privileges. ASUS has released patches; users should update Armoury Crate to the patched version.
Affected products
- ASUS Armoury Crate
Timeline
- 2026-09-08: disclosed