CVE-2026-75809 Details
Description
Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
A vulnerability in ASUS Armoury Crate has been identified, where an exposed IOCTL lacks proper access control. This flaw allows a local user to bypass driver authentication and manipulate PCIe configuration space, leading to unauthorized information disclosure and disruption of device functionality. The issue affects Armoury Crate versions through 6.5.7.0.
Users are advised to update to the latest version of ASUS Armoury Crate. Instructions for updating can be found on the ASUS Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asus.com/security-advisory | ASUS | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-782 | Exposed IOCTL with Insufficient Access Control | ASUS |
Affected Products
| Product | Versions |
|---|---|
| ASUS Armoury Crate | <= 6.5.7.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | ASUS |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | ASUS |
Volerion