Executive brief
ASUS Armoury Crate is a system utility that manages device settings and performance on ASUS computers. A vulnerability in the application's driver allows any local user to bypass authentication and access hardware configuration directly, potentially reading sensitive system information or disabling critical device features without proper authorization.
Technical details
The vulnerability stems from exposed IOCTL (I/O Control) handlers in the Armoury Crate driver that lack proper access control checks. An attacker with local system access can invoke these IOCTLs to read from and write to PCIe configuration space, bypassing the driver's intended authentication mechanism. No special privileges or user interaction are required beyond local code execution capability. A successful exploit enables information disclosure (reading hardware configuration and sensitive system data) and denial-of-service through device functionality disruption. ASUS has released a security update to address this issue.
Affected products
- ASUS Armoury Crate
Timeline
- 2026-09-08: disclosed