Executive brief
ASUS Armoury Crate is a system utility application used to manage device settings and peripherals. A local user can exploit insufficient resource controls in the application to exhaust system memory and cause a denial-of-service condition, making the system unresponsive or forcing a reboot.
Technical details
The vulnerability is a resource exhaustion flaw (CWE-770: Allocation of Resources Without Limits or Throttling) in ASUS Armoury Crate. The vulnerable component fails to enforce limits on memory allocation, and an attacker can bypass driver authentication to trigger unbounded memory allocation. This is a local-only attack requiring existing user access to the system. An attacker can achieve denial-of-service by exhausting available system memory. The vendor has released patches; users should apply the latest security update for Armoury Crate.
Affected products
- ASUS Armoury Crate <UNKNOWN>
Timeline
- 2026-09-08: disclosed