SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-18023

MEDIUM · CVSS 5.7 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ASUS Armoury Crate driver is vulnerable due to the failure to properly clear sensitive information from uninitialized memory, allowing local users to exploit this through crafted IOCTL requests and bypass security checks. This could lead to unauthorized disclosure of sensitive data. Organizations using ASUS Armoury Crate should prioritize applying the security update to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-18023
Severity
MEDIUM
CVSS
5.7
EPSS
0.09%

Original NVD Description

Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security Update for Armoury Crate AppĀ ' section on the ASUS Security Advisory for more information.