Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.09% | — | Asus Armoury CrateAI | 8/9/2026 | 17/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security… | |
| Aplazada | Media (5.8) | 0.09% | — | Asus Armoury CrateAI | 8/9/2026 | 17/9/2026 | Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App ' section on the ASUS… | |
| Aplazada | Media (5.9) | 0.09% | — | Asus Armoury CrateAI | 8/9/2026 | 17/9/2026 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more… | |
| Aplazada | Baja (2) | 0.09% | — | Asus Armoury CrateAI | 8/9/2026 | 17/9/2026 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for… | |
| Aplazada | Media (5.3) | 0.36% | — | Asus Armoury CrateAI | 8/9/2026 | 17/9/2026 | A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury… | |
| Aplazada | Media (5.8) | 0.14% | — | Asus Armoury CrateAI | 8/9/2026 | 28/9/2026 | Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the ' Security Update for Armoury Crate… | |
| Aplazada | Media (5.7) | 0.14% | — | Asus Armoury CrateAI | 8/9/2026 | 28/9/2026 | Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update… | |
| Aplazada | Media (5.9) | 0.14% | — | Asus Armoury CrateAI | 8/9/2026 | 28/9/2026 | Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security Update for Armoury Crate App ' section on… | |
| Aplazada | Media (5.7) | 0.14% | — | Asus Armoury CrateAI | 8/9/2026 | 28/9/2026 | Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security Update for Armoury Crate App ' section on the… | |
| Aplazada | Media (5.7) | 0.09% | — | Asus Armoury CrateAI | 8/9/2026 | 28/9/2026 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section… | |
| Aplazada | Alta (7.3) | 0.12% | — | Asus Armoury CrateAI | 30/7/2026 | 31/7/2026 | Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more… | |
| Aplazada | Alta (7.1) | 0.28% | — | Asus Armoury CrateAI | 22/6/2026 | 17/9/2026 | A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. | |
| Pendiente de análisis | Alta (7.3) | 0.11% | — | Asus Armoury CrateAI | 29/5/2026 | 17/9/2026 | Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. | |
| Aplazada | Media (4.8) | 0.12% | — | Asus Armoury CrateAI | 17/12/2025 | 17/6/2026 | An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or partial loss of functionality. This vulnerability only affects ASUS motherboard series products. Refer to the 'Security Update… | |
| Aplazada | Alta (7.3) | 0.12% | — | Asus Armoury CrateAI | 6/11/2025 | 17/6/2026 | A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury… | |
| Aplazada | Media (6.8) | 0.13% | — | Asus Armoury CrateAIAsus Asio3AI | 13/10/2025 | 17/6/2026 | A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (8.5) | 0.20% | — | Asus Armoury CrateAI | 13/10/2025 | 25/9/2026 | A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS… | |
| Aplazada | Alta (8.4) | 0.59% | — | Asus Armoury CrateAI | 16/6/2025 | 17/6/2026 | A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (8.2) | 0.29% | — | Asus Asio3.sysAIAsus Armoury CrateAI | 12/5/2025 | 17/6/2026 | A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information. | |
| Aplazada | Alta (8.4) | 0.16% | — | Asus Armoury CrateAI | 23/1/2025 | 17/6/2026 | A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information. | |
| Modificada | Crítica (9.8) | 0.63% | — | Asus Armoury Crate | 19/1/2024 | 17/6/2026 | ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission. | |
| Modificada | Alta (7.8) | 0.20% | — | Asus Armoury CrateSetupasusservices | 26/7/2023 | 9/7/2026 | ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. | |
| Modificada | Alta (7.8) | 0.16% | — | Asus Armoury Crate | 15/2/2023 | 17/6/2026 | ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS software products, contains multiple IOCTL handlers that provide raw read and write access to port I/O and MSRs via unprivileged IOCTL calls. Local users can gain… | |
| Modificada | Media (5.9) | 0.33% | — | Asus Armoury Crate Service | 28/9/2022 | 17/6/2026 | Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and… | |
| Modificada | Alta (7.3) | 0.40% | — | Asus Armoury Crate Lite Service | 27/9/2021 | 17/6/2026 | ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory. |