CVE-2026-18023: Medium severity ASUS Armoury Crate driver vulnerability
Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires local access to a system with the affected ASUS Armoury Crate driver. The attacker must be able to send a crafted IOCTL request to the driver.
What information could be exposed?
The issue can disclose sensitive information from uninitialized memory after a resource is reused without being removed. The provided information does not identify the specific data types that may be exposed.
What mitigation is available?
ASUS directs users to the “Security Update for Armoury Crate App” section of its security advisory. The provided information does not specify an alternative workaround if the update cannot be applied immediately.