Executive brief
ASUS Armoury Crate, a software suite used to manage and customize ASUS hardware settings, contains a vulnerability that could allow a local user to gain full control over the system. By exploiting a timing issue during file operations, an attacker with limited access can replace legitimate files with malicious ones. This could lead to unauthorized access to sensitive data, system-wide instability, or the installation of persistent malware.
Technical details
A race condition (CWE-362) exists in ASUS Armoury Crate versions V5.4.1 through V6.4.12 due to improper synchronization when accessing shared resources. A local attacker with low privileges can exploit this by timing a file replacement operation during a window of concurrent execution. Successful exploitation allows the attacker to execute arbitrary code with the elevated privileges of the Armoury Crate service. Users are advised to refer to the ASUS Security Advisory for update instructions to mitigate this vulnerability.
Affected products
- ASUS Armoury Crate V5.4.1 through V6.4.12
Timeline
- 2026-07-30: advisory: NVD publication date