CVE-2026-75811
- EPSS 0.11%
- Veröffentlicht 08.09.2026 03:17:19
- Zuletzt bearbeitet 28.09.2026 23:10:00
Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model...
CVE-2026-75810
- EPSS 0.11%
- Veröffentlicht 08.09.2026 03:17:18
- Zuletzt bearbeitet 28.09.2026 23:10:00
Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to ...
CVE-2026-75809
- EPSS 0.11%
- Veröffentlicht 08.09.2026 03:17:18
- Zuletzt bearbeitet 28.09.2026 23:10:00
Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration spa...
CVE-2026-75808
- EPSS 0.11%
- Veröffentlicht 08.09.2026 03:17:18
- Zuletzt bearbeitet 28.09.2026 23:10:00
Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory....
CVE-2026-18023
- EPSS 0.09%
- Veröffentlicht 08.09.2026 03:17:18
- Zuletzt bearbeitet 28.09.2026 23:10:00
Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mecha...
CVE-2026-16006
- EPSS 0.09%
- Veröffentlicht 08.09.2026 03:17:17
- Zuletzt bearbeitet 17.09.2026 09:16:39
Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing furthe...
CVE-2026-16005
- EPSS 0.09%
- Veröffentlicht 08.09.2026 03:17:17
- Zuletzt bearbeitet 17.09.2026 09:16:39
Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer t...
CVE-2026-16004
- EPSS 0.09%
- Veröffentlicht 08.09.2026 03:17:17
- Zuletzt bearbeitet 17.09.2026 09:16:39
Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for ...
- EPSS 0.09%
- Veröffentlicht 08.09.2026 03:17:17
- Zuletzt bearbeitet 17.09.2026 09:16:39
Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Upd...
CVE-2026-12962
- EPSS 0.36%
- Veröffentlicht 08.09.2026 03:17:17
- Zuletzt bearbeitet 17.09.2026 09:16:38
A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application...