CVE Tools

Armoury Crate

24 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Armoury Crate, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

Armoury Crate CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Armoury Crate CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-011
2025-020
2025-030
2025-040
2025-051
2025-061
2025-070
2025-080
2025-090
2025-103
2025-111
2025-121
2026-010
2026-020
2026-030
2026-040
2026-051
2026-061
2026-071
2026-080
2026-0910

Severity

How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical125%
  • High375%

Latest CVEs

The 15 most recently published vulnerabilities affecting Armoury Crate.

  1. CVE-2026-12962A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sen...—
  2. CVE-2026-18023Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request t...—
  3. CVE-2026-16003Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing ...—
  4. CVE-2026-16004Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the drive...—
  5. CVE-2026-16005Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt da...—
  6. CVE-2026-16006Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing t...—
  7. CVE-2026-75808Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentic...—
  8. CVE-2026-75809Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using I...—
  9. CVE-2026-75810Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management int...—
  10. CVE-2026-75811Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypass...—
  11. CVE-2026-16727Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a cr...—
  12. CVE-2026-8918A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation m...—
  13. CVE-2026-8070Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physic...—
  14. CVE-2025-11775An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or part...—
  15. CVE-2025-9338A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentia...—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store