CVE-2026-16003: Low severity ASUS Armoury Crate vulnerability
Published Sep 8, 2026
·Updated
Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Affected Software
1 affected component
ASUS Armoury Crate
Event History
Sep 8, 2026
CVE Published
via MITRE·02:03 AM
Data Sourced
via MITRE·02:03 AM
DescriptionWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A local user can exploit it. The issue is in the Armoury Crate driver and requires sending a crafted IOCTL request.
2
What does successful exploitation allow?
Successful exploitation allows the attacker to add an arbitrary process identifier to the driver's whitelist by bypassing the driver's verification.
3
Where can I find remediation information?
Refer to the “Security Update for Armoury Crate App” section of the ASUS Security Advisory.