CVE-2026-16003
Received Received - Intake

Exposed IOCTL Access Control Bypass in Armoury Crate Driver

Vulnerability report for CVE-2026-16003, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: ASUS

Description

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate AppΒ Β ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus armoury_crate *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-782 The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an exposed IOCTL (Input/Output Control) in the Armoury Crate driver that lacks sufficient access control. A local user can exploit this by sending a crafted IOCTL request to add an arbitrary process identifier to the driver's whitelist, bypassing verification mechanisms.

Detection Guidance

This vulnerability involves an exposed IOCTL with insufficient access control in the Armoury Crate driver. Detection requires checking for unauthorized modifications to the driver's whitelist or suspicious IOCTL requests. No specific commands are provided in the context.

Impact Analysis

A local attacker could potentially escalate privileges or execute unauthorized processes by manipulating the driver's whitelist. This may lead to system compromise, unauthorized access, or disruption of services relying on the Armoury Crate driver.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves a local privilege escalation in a driver component with limited impact. However, if exploited, it could potentially lead to unauthorized access to system resources, which may indirectly impact data protection measures required by these standards.

Mitigation Strategies

Update Armoury Crate to the latest version as per ASUS Security Advisory to address the insufficient access control in the driver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16003. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart