Insufficient Access Control in ASUS Armoury Crate Leads to Information Disclosure
CVE-2026-75809

5.9MEDIUM

Key Information:

Vendor

Asus

Vendor
CVE Published:
8 September 2026

What is CVE-2026-75809?

The ASUS Armoury Crate application exhibits a vulnerability due to inadequate access controls related to IOCTL operations. This flaw allows local users to bypass the driver authentication mechanisms, enabling them to manipulate the hardware through unauthorized access to the PCIe configuration space. As a result, sensitive information can be disclosed, and device functionalities can be compromised. Users are advised to consult the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for mitigation steps and further information.

Affected Version(s)

Armoury Crate 0 <= 6.5.7

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.