Junglewise Threat Intelligence

CVE-2026-8070: ASUS Armoury Crate incorrect permission assignment in driver

CVE-2026-8070 · Severity: info · CVSS 7.3 · Published 2026-05-29

Technologies: ASUS Armoury Crate. Vendors: ASUS.

Executive brief

A security vulnerability in the ASUS Armoury Crate software, which is used to manage and customize ASUS hardware settings, could allow a local user to gain unauthorized access to the computer's physical memory. This flaw could enable an attacker with limited access to read or modify sensitive system data, potentially leading to a full system takeover or the theft of confidential information. Users are advised to update the Armoury Crate application to the latest version to mitigate this risk.

Technical details

A vulnerability classified as Incorrect Permission Assignment (CWE-732) exists in the ASUS Armoury Crate application. The flaw resides in how the software manages permissions for a critical resource, which allows a local attacker with low privileges to bypass the driver's internal validation mechanisms. By successfully exploiting this bypass, the attacker can perform unauthorized read and write operations directly to physical memory. This level of access can be used to escalate privileges or execute arbitrary code at the kernel level. ASUS has addressed this in a security update for the Armoury Crate app.

Affected products

  • ASUS Armoury Crate

Timeline

  • 2026-05-29: advisory: NVD publication date
  • 2026-05-28: disclosed: ASUS reported the vulnerability to the CVE program

References

Related threats