CVE-2025-3464
published 2025-06-16CVE-2025-3464: A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication…
PriorityP343high8.4CVSS 4.0
AVLACLATNPRLUINVCLVIHVAHSCLSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.52%
40.5th percentile
A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass.
Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| asus | armoury_crate | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Asus and Adobe vulnerabilities
blogs_talos·2025-07-10·CVSS 8.2
[HIGH] Asus and Adobe vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed two vulnerabilities each in Asus Armoury Crate and Adobe Acrobat products.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.
## Asus Armoury Crate stack-based buffer overflow and authorization bypass vulnerabilities
Discovered by Marcin "Icewall" Noga of Cisco Talos.
These vulnerabilities were recently covered in a deep-dive post, Decrement by one to rule them all.
Asus Armoury Crate is
Talos
Asus and Adobe vulnerabilities
blogs_talos·2025-07-10·CVSS 8.2
[HIGH] Asus and Adobe vulnerabilities
## Asus and Adobe vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed two vulnerabilities each in Asus Armoury Crate and Adobe Acrobat products.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy .
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org , and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website .
## Asus Armoury Crate stack-based buffer overflow and authorization bypass vulnerabilities
Discovered by Marcin "Icewall" Noga of Cisco Talos.
These vulnerabilities were recently covered in a deep-dive post, Decrement by one to
Talos
Decrement by one to rule them all: AsIO3.sys driver exploitation
blogs_talos·2025-06-26·CVSS 8.2
[HIGH] Decrement by one to rule them all: AsIO3.sys driver exploitation
## Introduction
Armoury Crate and AI Suite are applications used to manage and monitor ASUS motherboards and related components such as the processor, RAM or the increasingly popular RGB lighting. These types of applications often install drivers in the system, which are necessary for direct communication with hardware to configure settings or retrieve critical parameters such as CPU temperature, fan speeds and firmware updates.
Therefore, it is critical to ensure that drivers are well-written with security in mind and designed such that access to the driver interfaces are limited only to certain services and administrators.
Figure 1. Armoury Crate application.
During the audit of the code and components related to the aforementioned applications, Cisco Talos discovered two critical vu
Talos
Decrement by one to rule them all: AsIO3.sys driver exploitation
blogs_talos·2025-06-26·CVSS 8.2
[HIGH] Decrement by one to rule them all: AsIO3.sys driver exploitation
## Decrement by one to rule them all: AsIO3.sys driver exploitation
## Introduction
Armoury Crate and AI Suite are applications used to manage and monitor ASUS motherboards and related components such as the processor, RAM or the increasingly popular RGB lighting. These types of applications often install drivers in the system, which are necessary for direct communication with hardware to configure settings or retrieve critical parameters such as CPU temperature, fan speeds and firmware updates.
Therefore, it is critical to ensure that drivers are well-written with security in mind and designed such that access to the driver interfaces are limited only to certain services and administrators.
During the audit of the code and components related to the aforementioned applications, Cisco T
Bleepingcomputer
ASUS Armoury Crate bug lets attackers get Windows admin privileges
blogs_bleepingcomputer·2025-06-16·CVSS 8.4
CVE-2025-3464 [HIGH] ASUS Armoury Crate bug lets attackers get Windows admin privileges
## ASUS Armoury Crate bug lets attackers get Windows admin privileges
## Bill Toulas
A high-severity vulnerability in ASUS Armoury Crate software could allow threat actors to escalate their privileges to SYSTEM level on Windows machines.
The security issue is tracked as CVE-2025-3464 and received a severity score of 8.8 out of 10.
It could be exploited to bypass authorization and affects the AsIO3.sys of the Armoury Crate system management software.
Armoury Crate is the official system control software for Windows from ASUS, providing a centralized interface to control RGB lighting (Aura Sync), adjust fan curves, manage performance profiles and ASUS peripherals, as well as download drivers and firmware updates.
To perform all these functions and provide low-level system monitoring, t
2025-06-16
Published