CVE-2026-18023
5.7
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ASUS | Armoury Crate | 0 <= 6.5.7 | affected |
Weaknesses
- CWE-226: CWE-226: Sensitive Information in Resource Not Removed Before Reuse
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.