CVE-2026-75809
Received Received - Intake

Exposed IOCTL in ASUS Armoury Crate allows local privilege escalation

Vulnerability report for CVE-2026-75809, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: ASUS

Description

Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus armoury_crate *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-782 The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an exposed IOCTL (Input/Output Control) in ASUS Armoury Crate with insufficient access control. A local user can bypass driver authentication to read from and write to PCIe configuration space. This allows them to disclose information and disable device functionality.

Detection Guidance

This vulnerability involves insufficient access control in ASUS Armoury Crate's IOCTL interface. Detection requires checking for unauthorized access to PCIe configuration space via driver interactions. No specific commands are provided in the context, but monitoring for unusual driver activity or unauthorized writes to PCIe space may indicate exploitation.

Impact Analysis

A local attacker could exploit this to access sensitive system information or disrupt device operations. This may lead to data leaks, system instability, or unauthorized changes to hardware settings.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face compliance penalties if exploited.

Mitigation Strategies

Update the ASUS Armoury Crate application to the latest version as recommended in the ASUS Security Advisory to address the exposed IOCTL issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75809. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart