File Handling Command Vulnerability in Armoury Crate by ASUS
CVE-2024-12957

8.4HIGH

Key Information:

Vendor
Asus
Vendor
CVE Published:
23 January 2025

Summary

A vulnerability exists in certain versions of the Armoury Crate application developed by ASUS, which allows for arbitrary file deletion due to improper handling of file commands. This flaw could be exploited to manipulate or delete important files without user consent, raising significant security concerns for affected systems. For detailed information and recommended mitigations, please refer to the official ASUS Security Advisory.

Affected Version(s)

Armoury Crate V2.3.4.0~V5.9.9.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.