CVE-2026-75808
Received Received - Intake

Allocation of Resources Without Limits in ASUS Armoury Crate

Vulnerability report for CVE-2026-75808, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: ASUS

Description

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus armoury_crate *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an allocation of resources without limits or throttling in ASUS Armoury Crate. A local user can cause a denial-of-service condition by bypassing driver authentication and allocating an unrestricted amount of memory, leading to system memory exhaustion.

Detection Guidance

Detection requires monitoring for abnormal memory allocation by the ASUS Armoury Crate application. Check for processes consuming excessive memory or system freezes. Review logs for driver authentication bypass attempts. Ensure Armoury Crate is updated to the latest version.

Impact Analysis

This vulnerability can impact you by causing your system to become unresponsive or crash due to memory exhaustion. It requires local access and the ability to bypass driver authentication, which may limit the risk to users with physical access to the device.

Compliance Impact

This vulnerability causes system memory exhaustion through unrestricted allocation, which could lead to denial-of-service conditions. Such disruptions may impact data availability, potentially violating compliance requirements for GDPR (data availability principles) and HIPAA (system availability for protected health information).

Mitigation Strategies

Update ASUS Armoury Crate to the latest version as per the ASUS Security Advisory to address the memory allocation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75808. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart