CVE-2026-16004 Details
Description
Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
A vulnerability in the Armoury Crate driver has been identified, allowing local users to read and write arbitrary PCI/PCIe configuration space. This issue arises from an exposed IOCTL that lacks sufficient access control, enabling users to bypass the driver's verification process with crafted IOCTL requests. The vulnerability affects Armoury Crate versions through 6.5.7.0.
Users are advised to update to the latest version of the Armoury Crate application. The update can be downloaded from the ASUS support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asus.com/security-advisory | ASUS | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-782 | Exposed IOCTL with Insufficient Access Control | ASUS |
Affected Products
| Product | Versions |
|---|---|
| ASUS Armoury Crate | <= 6.5.7.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | ASUS |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | ASUS |
Volerion