Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings… (CVE-2026-75811)
CVE-2026-75811 is a vulnerability in ASUS Armoury Crate where improper restriction of software interfaces to hardware features allows a local user to bypass driver authentication and modify hardware configuration settings. This can potentially lead to hardware damage by unauthorized access to critical model-specific registers. The vulnerability requires local access and has a medium severity rating.
AI Analysis
Technical Summary
The vulnerability in ASUS Armoury Crate involves improper restriction of software interfaces to hardware features, enabling a local user to bypass driver authentication mechanisms. This allows modification of hardware configuration settings and access to critical model-specific registers, which could potentially cause hardware damage. The issue is identified as CWE-1256 and has a moderate severity rating. No known exploits are reported in the wild, and no patch or remediation details are provided in the available data. The vulnerability affects local users with limited privileges and does not require user interaction.
Potential Impact
A local user with limited privileges can bypass driver authentication to modify hardware configuration settings, potentially causing hardware damage by accessing critical model-specific registers. There is no indication of remote exploitation or user interaction requirements. No known active exploitation has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the ASUS Security Advisory for current remediation guidance. Since no patch links or official fix information are provided, users should monitor ASUS advisories for updates. Until a fix is available, restricting local access to trusted users and limiting permissions may reduce risk.
Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings… (CVE-2026-75811)
Description
CVE-2026-75811 is a vulnerability in ASUS Armoury Crate where improper restriction of software interfaces to hardware features allows a local user to bypass driver authentication and modify hardware configuration settings. This can potentially lead to hardware damage by unauthorized access to critical model-specific registers. The vulnerability requires local access and has a medium severity rating.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in ASUS Armoury Crate involves improper restriction of software interfaces to hardware features, enabling a local user to bypass driver authentication mechanisms. This allows modification of hardware configuration settings and access to critical model-specific registers, which could potentially cause hardware damage. The issue is identified as CWE-1256 and has a moderate severity rating. No known exploits are reported in the wild, and no patch or remediation details are provided in the available data. The vulnerability affects local users with limited privileges and does not require user interaction.
Potential Impact
A local user with limited privileges can bypass driver authentication to modify hardware configuration settings, potentially causing hardware damage by accessing critical model-specific registers. There is no indication of remote exploitation or user interaction requirements. No known active exploitation has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the ASUS Security Advisory for current remediation guidance. Since no patch links or official fix information are provided, users should monitor ASUS advisories for updates. Until a fix is available, restricting local access to trusted users and limiting permissions may reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p99v-4cq5-g69c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-75811"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a9f9105acd9273b49ff2529
Added to database: 09/08/2026, 04:37:25 UTC
Last enriched: 09/08/2026, 05:39:20 UTC
Last updated: 09/08/2026, 07:51:59 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.