Executive brief
ASUS Armoury Crate is a system utility that manages hardware settings on ASUS computers. A local attacker with user-level access can bypass driver authentication controls to directly access hardware registers and modify system hardware configuration, potentially causing permanent hardware damage or disabling security features.
Technical details
This vulnerability stems from improper restriction of software interfaces to hardware features (CWE-1232) in ASUS Armoury Crate. The application fails to properly enforce authentication checks before allowing access to model-specific registers (MSRs) and other privileged hardware interfaces through kernel drivers. A local attacker with standard user privileges can bypass these authentication controls to directly manipulate critical hardware settings. The vulnerability requires local code execution and does not require elevated privileges to trigger. Impact includes unauthorized modification of hardware configuration, potential system instability, and risk of permanent hardware damage.
Affected products
- ASUS Armoury Crate <UNKNOWN>
Timeline
- 2026-09-08: disclosed