CVE-2025-3464 Details
Description
A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
A race condition vulnerability has been identified in the ASUS Armoury Crate application. This vulnerability is a Time-of-check Time-of-use (TOCTOU) issue, which could potentially lead to an authentication bypass.
Users can refer to the ASUS Product Security Advisory page for the latest security update information for the Armoury Crate App.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 16, 2025CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2025-2150 | ASUS | |
| https://www.asus.com/content/asus-product-security-advisory/ | ASUS | AdvisoryRemedyVendor |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2150 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | ASUS |
Affected Products
| Product | Versions |
|---|---|
| ASUS Armoury Crate | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ASUS |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2025 | CVE Modified | ASUS |
| Jun 16, 2025 | CVE Modified | CVE |
| Jun 16, 2025 | New CVE Received | ASUS |
Volerion