CVE-2026-75811
Received Received - Intake

Improper Hardware Interface Access in ASUS Armoury Crate

Vulnerability report for CVE-2026-75811, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: ASUS

Description

Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asus armoury_crate *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1256 The product provides software-controllable device functionality for capabilities such as power and clock management, but it does not properly limit functionality that can lead to modification of hardware memory or register bits, or the ability to observe physical side channels.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper restrictions in ASUS Armoury Crate software that allow a local user to bypass driver authentication. This enables modification of hardware configuration settings and potential hardware damage by accessing critical model-specific registers.

Detection Guidance

This vulnerability involves improper hardware interface restrictions in ASUS Armoury Crate. Detection requires checking for unauthorized modifications to hardware settings or model-specific registers. Review ASUS Armoury Crate logs for suspicious activity and verify driver authentication bypass attempts.

Impact Analysis

A local attacker could exploit this to change hardware settings, potentially causing permanent damage to components like CPU or GPU. It may also lead to system instability or reduced hardware lifespan.

Compliance Impact

The vulnerability allows unauthorized modification of hardware settings, which could lead to data integrity issues or unauthorized access to sensitive information. This may impact compliance with GDPR (data protection) and HIPAA (healthcare data security) by potentially exposing or altering protected data.

Mitigation Strategies

Update ASUS Armoury Crate to the latest version as per the ASUS Security Advisory to address the improper restriction issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75811. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart