CVE-2026-16004
Received Received - Intake

Exposed IOCTL with Insufficient Access Control in Armoury Crate

Vulnerability report for CVE-2026-16004, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: ASUS

Description

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus armoury_crate *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-782 The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an exposed IOCTL (Input/Output Control) in the Armoury Crate driver that lacks sufficient access control. A local user can exploit this to read and write arbitrary PCI/PCIe configuration space by sending crafted IOCTL requests, bypassing the driver's verification mechanisms.

Detection Guidance

This vulnerability involves an exposed IOCTL in the Armoury Crate driver that allows local users to read and write arbitrary PCI/PCIe configuration space. Detection requires checking for unauthorized access to the driver's IOCTL interface or suspicious PCI configuration modifications. No specific commands are provided in the context, but monitoring for unusual driver interactions or PCI configuration changes may help.

Impact Analysis

This vulnerability allows a local attacker to manipulate PCI/PCIe configuration space, potentially leading to unauthorized access, system instability, or privilege escalation. It could enable data theft, system crashes, or unauthorized hardware modifications.

Compliance Impact

This vulnerability allows local users to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests, bypassing driver verification. This could lead to unauthorized access to sensitive system data, potentially violating data protection requirements under GDPR and HIPAA if exploited.

Mitigation Strategies

Update the Armoury Crate application to the latest version as per the ASUS Security Advisory to address the exposed IOCTL with insufficient access control issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16004. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart