Junglewise Threat Intelligence

CVE-2026-18023: ASUS Armoury Crate driver sensitive information disclosure

CVE-2026-18023 · Severity: info · Published 2026-09-08

Technologies: ASUS Armoury Crate. Vendors: ASUS.

Executive brief

ASUS Armoury Crate is a driver component used to manage system hardware and performance settings on ASUS computers. A local user with access to the system can exploit a flaw in the driver's memory handling to read sensitive information from uninitialized memory by sending specially crafted requests, potentially exposing system credentials or other confidential data.

Technical details

This vulnerability is a use-after-free or uninitialized memory disclosure in the ASUS Armoury Crate driver. An attacker with local system access can send a crafted IOCTL (I/O Control) request to the driver that bypasses its security verification mechanism, allowing direct access to uninitialized kernel or driver memory. The vulnerability requires local access and does not require authentication or elevated privileges beyond local user access. An attacker can read sensitive data from memory that should have been cleared before reuse. A security patch is available from ASUS and should be applied immediately.

Affected products

  • ASUS Armoury Crate

Timeline

  • 2026-09-08: disclosed

References

Related threats