SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16006

MEDIUM · CVSS 5.7 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Armoury Crate driver is vulnerable to a local user exploiting a crafted IOCTL request, which bypasses the driver's verification mechanisms, allowing access to sensitive kernel virtual addresses. This exposure could lead to further insights into the kernel memory layout, potentially facilitating additional attacks. Organizations using the Armoury Crate driver should prioritize patching this vulnerability to mitigate the risk of unauthorized access to sensitive system information.

CVE
CVE-2026-16006
Severity
MEDIUM
CVSS
5.7
EPSS
0.09%

Original NVD Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel memory layout.Refer to the ' Security Update for Armoury Crate App  ' section on the ASUS Security Advisory for more information.