CVE-2026-16005
Received Received - Intake

Memory Corruption in Armoury Crate Driver via IOCTL Request

Vulnerability report for CVE-2026-16005, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: ASUS

Description

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate AppΒ Β ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus armoury_crate *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-763 The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the Armoury Crate driver where a local user can exploit a crafted IOCTL request to free arbitrary memory. The driver fails to properly verify the request, allowing bypass of its verification checks. This can corrupt critical data structures, leading to a system crash such as a Blue Screen of Death (BSOD).

Detection Guidance

This vulnerability involves a crafted IOCTL request exploiting the Armoury Crate driver. Detection may require monitoring for abnormal driver behavior or system crashes. Check for BSOD events and inspect driver logs for unexpected memory free operations.

Impact Analysis

This vulnerability allows a local attacker to cause a system crash, resulting in data loss and disruption of services. It may also enable further exploitation if combined with other vulnerabilities, potentially leading to unauthorized access or privilege escalation on the affected system.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves a local privilege escalation and system crash via a driver flaw. GDPR and HIPAA focus on data protection and privacy, which are not directly impacted by this issue.

Mitigation Strategies

Apply the security update for Armoury Crate as referenced in the ASUS Security Advisory. Disable or restrict access to the vulnerable driver if an update is not immediately available. Monitor system stability and BSOD occurrences.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16005. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart