SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16004

MEDIUM · CVSS 5.9 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Armoury Crate driver has an exposed IOCTL with insufficient access control, allowing local users to read and write arbitrary PCI/PCIe configuration space through crafted IOCTL requests, effectively bypassing the driver's verification mechanisms. This vulnerability could lead to unauthorized access and manipulation of hardware configurations, potentially compromising system integrity. Organizations using affected ASUS products should prioritize this issue to mitigate risks associated with local privilege escalation and hardware manipulation.

CVE
CVE-2026-16004
Severity
MEDIUM
CVSS
5.9
EPSS
0.09%

Original NVD Description

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.