Insufficient Access Control in Armoury Crate Driver by ASUS
CVE-2026-16004

5.9MEDIUM

Key Information:

Vendor

Asus

Vendor
CVE Published:
8 September 2026

What is CVE-2026-16004?

The Armoury Crate driver contains a vulnerability that exposes IOCTL operations with insufficient access control measures. This flaw enables local users to manipulate the PCI/PCIe configuration space by crafting specific IOCTL requests, thus bypassing the necessary verification mechanisms. Such exposure can lead to unauthorized access and manipulation of system-level configurations. It is crucial for users of the Armoury Crate driver to refer to the ASUS Security Advisory for detailed information on the required security updates.

Affected Version(s)

Armoury Crate 0 <= 6.5.7

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vladimirelitokarev@gmail.com
beta_b0t@yahoo.com
geraldlim619@gmail.com
.