hardware
High-severity CVE-2026-8917 affects Asus Armoury Crate, GPU Tweak and AI Suite
A new high-severity vulnerability (CVE-2026-8917, 8.4/10) was found in components used by Asus Armoury Crate, GPU Tweak II, GPU Tweak III and AI Suite 3. The flaw is an IOCTL issue that allows a local attacker to write a specific value to an arbitrary memory address, potentially enabling privilege escalation. Updates are available: Armoury Crate can be updated from within the app, while GPU Tweak II/III and AI Suite 3 require downloads from Asus support pages. This matters because the vulnerability gives local attackers a concrete path to escalate privileges on affected systems.
- CVE-2026-8917 carries a severity score of 8.4/10 and is classified as high severity.
- The vulnerability is an IOCTL bug that permits a local attacker to write a specific value to an arbitrary memory address, which can lead to privilege escalation.
- Affected software includes Armoury Crate (via a vulnerable component), Asus GPU Tweak III, GPU Tweak II and AI Suite 3.
- Armoury Crate updates are available inside the application; GPU Tweak II/III and AI Suite 3 updates must be downloaded from Asus support pages.