Armoury Crate Asus Armoury Crate

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Asus Armoury Crate.

By the Year

In 2026 there have been 13 vulnerabilities in Asus Armoury Crate with an average score of 5.7 out of ten. Last year, in 2025 Armoury Crate had 8 security vulnerabilities published. That is, 5 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 13 5.66
2025 8 0.00
2024 1 9.80
2023 2 7.80
2022 1 5.90

It may take a day or so for new Armoury Crate vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Asus Armoury Crate Security Vulnerabilities

Armoury Crate NTLM Hash Leak via CrossDomain Policy
CVE-2026-12962 5.3 - Medium - September 08, 2026

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Permissive Cross-domain Policy with Untrusted Domains

ASUS Armoury Crate Driver IOCTL Local Info Disclosure via Uninitialized Memory
CVE-2026-18023 5.7 - Medium - September 08, 2026

Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Sensitive Information in Resource Not Removed Before Reuse

Armoury Crate Driver Local Priv Esc via Insufficient IOCTL ACL
CVE-2026-16003 2 - Low - September 08, 2026

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.

Exposed IOCTL with Insufficient Access Control

Armoury Crate Driver IOCTL Priv Escalation via PCI Config Space
CVE-2026-16004 5.9 - Medium - September 08, 2026

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

Exposed IOCTL with Insufficient Access Control

Armoury Crate Driver Release Invalid Ptr Free Causing BSOD
CVE-2026-16005 5.8 - Medium - September 08, 2026

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.

Release of Invalid Pointer or Reference

Armoury Crate driver IOCTL local privileged info leak to kernel addresses
CVE-2026-16006 5.7 - Medium - September 08, 2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.

Exposure of Sensitive System Information to an Unauthorized Control Sphere

ASUS Armoury Crate Unrestricted Memory Allocation DoS via Driver Auth Bypass
CVE-2026-75808 5.7 - Medium - September 08, 2026

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Allocation of Resources Without Limits or Throttling

ASUS Armoury Crate IOCTL Access Control Flaw Enables Local Info Disclosure
CVE-2026-75809 5.9 - Medium - September 08, 2026

Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Exposed IOCTL with Insufficient Access Control

Local DoS via SMI Trigger in ASUS Armoury Crate
CVE-2026-75810 5.7 - Medium - September 08, 2026

Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Exposed Dangerous Method or Function

Local Privilege Escalation in ASUS Armoury Crate via Register Access
CVE-2026-75811 5.8 - Medium - September 08, 2026

Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

Hardware Features Enable Physical Attacks from Software

Armoury Crate Race Condition PVE via File Replacement (CVE-2026-16727)
CVE-2026-16727 - July 30, 2026

Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.

Race Condition

Arbitrary Mem RW via Input Bypass in ASUS Armoury Crate
CVE-2026-8918 7.1 - High - June 22, 2026

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

Allowlist / Allow List

Armoury Crate Local Permission Elevation Bypass (CVE-2026-8070)
CVE-2026-8070 7.3 - High - May 29, 2026

Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the drivers validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the '  Security Update for Armoury Crate App   ' section on the ASUS Security Advisory for more information.

Incorrect Permission Assignment for Critical Resource

ASUS asComSvc OOB Read in Armoury Crate
CVE-2025-11775 - December 17, 2025

An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or partial loss of functionality. This vulnerability only affects ASUS motherboard series products. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

Out-of-bounds Read

ASUS Armoury Crate AsIO3.sys Local Privilege Escalation via Buffer Overflow
CVE-2025-9338 - November 06, 2025

A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.

Buffer Overflow

ASUS AsIO3.sys NPE Crash in Armoury Crate
CVE-2025-9337 - October 13, 2025

A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

NULL Pointer Dereference

Buffer Overflow in AsIO3.sys driver of Asus Armoury Crate
CVE-2025-9336 - October 13, 2025

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

Stack Overflow

Armoury Crate UnifyScanner Link-Following PrivEsc Vulnerability
CVE-2025-9968 - October 13, 2025

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS Security Advisory.

insecure temporary file

Armoury Crate Race Condition TTOU Auth Bypass (CVE-2025-3464)
CVE-2025-3464 - June 16, 2025

A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

ASIO3.sys Buffer Overflow in ASUS Armoury Crate Driver
CVE-2025-1533 - May 12, 2025

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

Arbitrary File Deletion via File Handling in Armoury Crate
CVE-2024-12957 - January 23, 2025

A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer to the '01/23/2025 Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

ASUS Armoury Crate: Arbitrary File Write via HTTP (CVE-2023-5716)
CVE-2023-5716 9.8 - Critical - January 19, 2024

ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.

Missing Authentication for Critical Function

ASUS SetupAsusServices v1.0.5.1 unquoted svc path -> local privilege escalation (Armoury Crate <5.3.
CVE-2023-26911 - July 26, 2023

ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

ASUS EC Tool Driver (d.sys) Priv Esc via Unprivileged IOCTL
CVE-2022-42455 7.8 - High - February 15, 2023

ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS software products, contains multiple IOCTL handlers that provide raw read and write access to port I/O and MSRs via unprivileged IOCTL calls. Local users can gain privileges.

Armoury Crate Log SYMLINK Overwrite CVE-2022-38699
CVE-2022-38699 5.9 - Medium - September 28, 2022

Armoury Crate Services logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.

insecure temporary file

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Asus Armoury Crate or by Asus? Click the Watch button to subscribe.

Asus
Vendor

subscribe