CVE-2026-16004: Medium severity ASUS Armoury Crate driver vulnerability
Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems with the ASUS Armoury Crate driver installed are exposed because the affected driver accepts crafted IOCTL requests from a local user.
What level of access does an attacker need?
An attacker needs local access to the system. The issue is exploited through crafted IOCTL requests to bypass the driver's verification.
What could an attacker do after exploiting the flaw?
The attacker could read and write arbitrary PCI/PCIe configuration space through the Armoury Crate driver.
How should this be remediated?
Consult the ASUS Security Advisory and its “Security Update for Armoury Crate App” section for the available security update information.