Insufficient Access Control in ASUS Armoury Crate Leads to Information Disclosure
CVE-2026-75809
5.9MEDIUM
What is CVE-2026-75809?
The ASUS Armoury Crate application exhibits a vulnerability due to inadequate access controls related to IOCTL operations. This flaw allows local users to bypass the driver authentication mechanisms, enabling them to manipulate the hardware through unauthorized access to the PCIe configuration space. As a result, sensitive information can be disclosed, and device functionalities can be compromised. Users are advised to consult the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for mitigation steps and further information.
Affected Version(s)
Armoury Crate 0 <= 6.5.7