SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-16003

LOW · CVSS 2 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Armoury Crate driver has an exposed IOCTL with insufficient access control, enabling local users to manipulate the driver's whitelist by sending crafted IOCTL requests that bypass verification. This vulnerability could allow unauthorized processes to gain elevated privileges, potentially leading to further exploitation of the system. Organizations using the Armoury Crate driver should prioritize applying security updates to mitigate this risk.

CVE
CVE-2026-16003
Severity
LOW
CVSS
2
EPSS
0.09%

Original NVD Description

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.