Junglewise Threat Intelligence

CVE-2026-16005: ASUS Armoury Crate driver use-after-free via IOCTL

CVE-2026-16005 · Severity: info · CVSS 6.5 · Published 2026-09-08

Technologies: ASUS Armoury Crate. Vendors: ASUS.

Executive brief

The ASUS Armoury Crate driver contains a memory management vulnerability that allows a local attacker with limited privileges to crash the system or corrupt memory through a specially crafted driver command. This could lead to data loss, system instability, or provide a stepping stone for further attacks on affected ASUS computers.

Technical details

The Armoury Crate driver is vulnerable to a use-after-free (release of invalid pointer) condition in its IOCTL request handling. An attacker can bypass the driver's input verification and supply a crafted IOCTL request that causes the driver to free an arbitrary memory address, leading to memory corruption and triggering a blue screen of death (BSOD). The vulnerability requires local access to the system but does not require elevated privileges. ASUS has released patches; users should update Armoury Crate to the patched version.

Affected products

  • ASUS Armoury Crate

Timeline

  • 2026-09-08: disclosed

References

Related threats