CVE-2026-19397 is a high-severity vulnerability affecting ASUS Control Center Express Agent. The vulnerability has a CVSS v4.0 score of 7.7 and is classified as CWE-306, Missing Authentication for Critical Function. It affects ASUS Control Center Express Agent versions earlier than v1.7.24. The vulnerability occurs due to insufficient authentication for a critical function within the affected agent. An unauthenticated nearby attacker may exploit the issue by establishing a direct connection to the agent. Successful exploitation requires the targeted host to have an active user login session. The attacker could potentially gain control over the affected host without requiring valid credentials. This vulnerability may impact the confidentiality, integrity, and availability of the affected system.
CVE-2026-16004 (CVSS 5.9) : Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification.[/subscribe_to_unlock_form]
CVE-2026-19397 is a high-severity vulnerability affecting ASUS Control Center Express Agent. The vulnerability has a CVSS v4.0 score of 7.7 and is classified as CWE-306, Missing Authentication for Critical Function. It affects ASUS Control Center Express Agent versions earlier than v1.7.24. The vulnerability occurs due to insufficient authentication for a critical function within the affected agent. An unauthenticated nearby attacker may exploit the issue by establishing a direct connection to the agent. Successful exploitation requires the targeted host to have an active user login session. The attacker could potentially gain control over the affected host without requiring valid credentials. This vulnerability may impact the confidentiality, integrity, and availability of the affected system.
CVE-2026-16004 (CVSS 5.9) : Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification.[emaillocker id="1283"]
CVE-2026-75809 (CVSS 5.9) : Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.
CVE-2026-16005 (CVSS 5.8) : Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).
CVE-2026-75811 (CVSS 5.8) : Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.
CVE-2026-16006 (CVSS 5.7) : exposure of sensitive system information vulnerability in the ASUS Armoury Crate driver. A local user with low privileges can send a crafted IOCTL request that bypasses the driver’s verification mechanism, allowing them to obtain kernel virtual addresses and gain insight into the kernel memory layout.
CVE-2026-18023 (CVSS 5.7) : Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism.
CVE-2026-75808 (CVSS 5.7) : allocation of resources without limits or throttling flaw. A local user with low privileges can bypass driver authentication and allocate an unrestricted amount of system memory, leading to a denial-of-service condition through memory exhaustion.
We recommend you to update Control Center Express to the version 1.7.24 or later.
The following reports contain further technical details:
[/emaillocker]