A high-severity vulnerability associated with an ASUS system-management component could allow a local attacker to elevate privileges by abusing driver input/output controls. The vulnerability is tracked as CVE-2026-8917 and has a reported CVSS score of 8.4. It involves an IOCTL interface capable of writing attacker-controlled values to sensitive memory locations. Successful exploitation requires local access and the ability to execute code. It is consequently not an unauthenticated remote compromise, but malware or a restricted local account could potentially use it to gain greater control. The affected component is distributed with ASUS management and tuning software used across gaming notebooks, desktops and handheld systems, including products related to Armoury Crate. Reports specifically include ASUS gaming laptops and the ROG Xbox Ally X among potentially exposed devices.
ASUS published an advisory on August 10 and recommends installing current application and driver updates. Users should open Armoury Crate’s Update Center and apply every available component update rather than updating only the visible main application.
ASUS has also released security-related updates for GPU Tweak III, GPU Tweak II and AI Suite 3. The current GPU Tweak III release referenced in the report is version 2.1.7.2.
Kernel-level hardware utilities have extensive privileges because they need direct access to sensors, registers and power controls. That makes tightly validating every user-supplied command particularly important.
ASUS ROG PG34WCDN Tandem RGB OLED Offers 3440×1440 at 360Hz
Beelink ME Pro NAS Mini PC Gets Ryzen AI 9 HX 470
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
