Junglewise Threat Intelligence

CVE-2026-16006: ASUS Armoury Crate kernel virtual address disclosure via IOCTL

CVE-2026-16006 · Severity: info · Published 2026-09-08

Technologies: ASUS Armoury Crate. Vendors: ASUS.

Executive brief

The ASUS Armoury Crate driver contains a vulnerability that allows a local user to obtain kernel virtual addresses through a specially crafted request, bypassing the driver's access controls. This information disclosure could help an attacker map the kernel memory layout, enabling targeted exploitation of other kernel vulnerabilities for privilege escalation or system compromise.

Technical details

The vulnerability is an information disclosure flaw in the Armoury Crate driver where insufficient verification of IOCTL (input/output control) requests allows a local attacker to extract kernel virtual addresses. An authenticated local user can craft a malicious IOCTL request that bypasses the driver's validation checks and exposes kernel memory layout information. This does not enable direct code execution but provides valuable reconnaissance data (KASLR bypass) that could facilitate further attacks. The issue affects the Armoury Crate driver and is patched in the latest driver version available through ASUS security updates.

Affected products

  • ASUS Armoury Crate

Timeline

  • 2026-09-08: disclosed

References

Related threats