Executive brief
ASUS Armoury Crate, a software suite used to manage and customize ASUS gaming hardware, contains a security flaw in how it validates user input. A local user with administrative privileges can exploit this to read or write to system memory or cause the computer to crash with a Blue Screen of Death (BSOD). This could lead to a complete loss of system stability or the compromise of sensitive data stored in memory.
Technical details
A vulnerability classified as CWE-183 (Permissive List of Allowed Inputs) exists in ASUS Armoury Crate versions 6.4.12 and earlier. The software fails to properly restrict or validate specific inputs, allowing a local attacker with high privileges (Administrator) to bypass validation mechanisms. Successful exploitation enables arbitrary memory read and write operations or the ability to trigger a kernel-level system crash (BSOD). While the attack requires local access and high privileges, it allows for significant manipulation of system memory. Users are advised to refer to the ASUS Security Advisory for update instructions.
Affected products
- ASUS Armoury Crate <= 6.4.12
Timeline
- 2026-06-22: disclosed: Initial publication of CVE-2026-8918