CVE-2026-16006: Medium severity ASUS Armoury Crate driver vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user can exploit it. The issue is in the ASUS Armoury Crate driver and requires sending a crafted IOCTL request to that driver.
What information could exploitation expose?
The vulnerability can disclose kernel virtual addresses, giving an attacker insight into the kernel memory layout. The provided information does not state that it directly enables code execution or privilege escalation.
How can I determine whether a system may be affected?
Check whether the ASUS Armoury Crate driver is installed and consult the ASUS Security Advisory's “Security Update for Armoury Crate App” section for affected-version and update information.