CVE-2026-12962
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L
Summary
A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ASUS | Armoury Crate | 0 <= 6.5.7.0 | affected |
Weaknesses
- CWE-942: CWE-942: Permissive Cross-domain Security Policy with Untrusted Domains
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.