SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16005

MEDIUM · CVSS 5.8 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Armoury Crate driver is vulnerable to a release of invalid pointer or reference, allowing local users to exploit crafted IOCTL requests to free arbitrary memory. This can lead to data structure corruption and potentially cause a system crash (BSOD). Organizations using affected ASUS products should prioritize this vulnerability to mitigate risks associated with system stability and data integrity.

CVE
CVE-2026-16005
Severity
MEDIUM
CVSS
5.8
EPSS
0.09%

Original NVD Description

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.