CVE-2025-9338: ASUS Armoury Crate

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.

Affected products

  • ASUS Armoury Crate: up to and including 6.2.11

Published 2025-11-06. Last modified 2026-10-07.