Insufficient Access Control in Armoury Crate Driver by ASUS
CVE-2026-16003
2LOW
What is CVE-2026-16003?
The Armoury Crate driver presents a significant security risk due to an exposed IOCTL that allows local users to manipulate access controls. By sending a specially crafted IOCTL request, users can potentially add any process identifier to the driver's whitelist, thereby bypassing the intended verification mechanisms. This vulnerability highlights the importance of stringent access controls within device drivers to prevent unauthorized modifications and ensure system integrity. For detailed information, refer to the ASUS Security Advisory.
Affected Version(s)
Armoury Crate 0 <= 6.5.7
References
CVSS V4
Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
vladimirelitokarev@gmail.com
beta_b0t@yahoo.com
geraldlim619@gmail.com