Asus
Asus Armoury Crate: vulnerabilidades y CVE
Asus Armoury Crate tiene 23 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses17
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-16006 | Media (5.7) | 0.09% | — | 8 sept 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's… |
| CVE-2026-16005 | Media (5.8) | 0.09% | — | 8 sept 2026 | Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and… |
| CVE-2026-16004 | Media (5.9) | 0.09% | — | 8 sept 2026 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification.… |
| CVE-2026-16003 | Baja (2) | 0.09% | — | 8 sept 2026 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's… |
| CVE-2026-12962 | Media (5.3) | 0.36% | — | 8 sept 2026 | A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request… |
| CVE-2026-75811 | Media (5.8) | 0.14% | — | 8 sept 2026 | Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver… |
| CVE-2026-75810 | Media (5.7) | 0.14% | — | 8 sept 2026 | Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs).… |
| CVE-2026-75809 | Media (5.9) | 0.14% | — | 8 sept 2026 | Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and… |
| CVE-2026-75808 | Media (5.7) | 0.14% | — | 8 sept 2026 | Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an… |
| CVE-2026-18023 | Media (5.7) | 0.09% | — | 8 sept 2026 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the… |
| CVE-2026-16727 | Alta (7.3) | 0.12% | — | 30 jul 2026 | Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement.… |
| CVE-2026-8918 | Alta (7.1) | 0.28% | — | 22 jun 2026 | A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the… |
| CVE-2026-8070 | Alta (7.3) | 0.11% | — | 29 may 2026 | Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the '… |
| CVE-2025-11775 | Media (4.8) | 0.12% | — | 17 dic 2025 | An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or partial loss of… |
| CVE-2025-9338 | Alta (7.3) | 0.12% | — | 6 nov 2025 | A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local… |
| CVE-2025-9337 | Media (6.8) | 0.13% | — | 13 oct 2025 | A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the 'Security Update for Armoury… |
| CVE-2025-9968 | Alta (8.5) | 0.20% | — | 13 oct 2025 | A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For… |
| CVE-2025-3464 | Alta (8.4) | 0.59% | — | 16 jun 2025 | A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate… |
| CVE-2025-1533 | Alta (8.2) | 0.29% | — | 12 may 2025 | A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the… |
| CVE-2024-12957 | Alta (8.4) | 0.16% | — | 23 ene 2025 | A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security Update for Armoury Crate App' section on the ASUS Security Advisory for… |
| CVE-2023-5716 | Crítica (9.8) | 0.63% | — | 19 ene 2024 | ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission. |
| CVE-2023-26911 | Alta (7.8) | 0.20% | — | 26 jul 2023 | ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. |
| CVE-2022-42455 | Alta (7.8) | 0.16% | — | 15 feb 2023 | ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS software products, contains multiple IOCTL handlers that provide raw… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.