Untrusted Pointer Dereference in ASUS GPU Tweak and AI Suite
CVE-2026-8917

8.4HIGH

Key Information:

Vendor

Asus

Vendor
CVE Published:
11 August 2026

What is CVE-2026-8917?

A vulnerability in ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate allows a local attacker to exploit IOCTL functionality to write arbitrary values to designated memory addresses, which may lead to elevated privileges within the affected systems. This can pose significant security risks, making it crucial for users to apply available security updates provided by ASUS.

Affected Version(s)

AI Suite3 0

GPU Tweak III 0

GPUTweakII 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Angelo Frasca Caccia
SentinelOne
.