Executive brief
ASUS Armoury Crate is a system management utility that controls device lighting, cooling, and performance settings. A local attacker can bypass driver authentication and trigger system management interrupts (SMIs) that briefly stall the system. Repeated exploitation could render the system unresponsive, disrupting user productivity.
Technical details
The vulnerability is an exposed dangerous method or function in ASUS Armoury Crate that fails to properly validate or authenticate access to privileged operations. An attacker with local access can bypass driver authentication mechanisms and invoke system management interrupt (SMI) handlers without proper authorization. By repeatedly triggering SMIs, an attacker can cause denial-of-service conditions characterized by system stalls. The attack requires local user-level access but does not require elevated privileges. A patch is available through ASUS's Security Update for Armoury Crate App.
Affected products
- ASUS Armoury Crate
Timeline
- 2026-09-08: disclosed