ASUS confirms security flaws in Armoury Crate, GPU Tweak III, and more
ASUS issues security guidance for GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate
ASUS has recommended that users of its GPU Tweak 3, GPU Tweak II, Armoury Crate, and AI Suite 3 software update to their latest versions. Security flaws have been uncovered in these applications, and ASUS has mitigated them through software updates.
For “optimal protection”, users of these software tools should update to the latest versions of these tools. The issue affecting these tools is called CVE-2026-8917, and it has been given a CVSS score of 8.4. This flaw has a high security rating.
Note that this is not the first time that ASUS’ Armoury Crate software has needed to be updated on security grounds. Last year, ASUS had to update Armoury Crate and other software packages due to other security issues. Details about this are available here.
ASUS has released security updates for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and a component used by Armoury Crate, and recommends updating to the latest versions to ensure optimal protection.
This update addresses a security vulnerability in these products. If exploited, the issue could allow a local user to escalate privileges on the system.
ASUS strongly recommends that users update the affected software to the fixed versions listed below immediately.
For GPU Tweak III, GPU Tweak II, and AI Suite 3, please download and install the applicable or latest version from the ASUS Support site. For Armoury Crate, the latest update can be received by opening the application and clicking “Check for Updates” in its update center.CVE-2026-8917
CVSS 4.0 Score:8.4 / High– ASUS
Using this exploit, local attackers can write specific values to arbitrary memory addresses, potentially allowing for a privilege escalation. Thankfully, this isn’t an attack that bad actors can trigger remotely. Regardless, users of these ASUS softwares should update their systems to fully secure their systems.
Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the ‘ Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin
– CVE.org
Affected versions
- ASUS GPU Tweak III – Versions 0-V2.1.1.7
- ASUS GPU Tweak II – Version 0-V2.4.0.0
- ASUS AI Suite 3 – Version 0-V2.1.2.0
- (VGAdll) Armory Crate Component – Version 0-V0.0.7.8
Users of ASUS’ GPU Tweak 3, GPU Tweak II, and AI Suite 3 software should download their latest versions from ASUS. Note that Armoury Crate users can simply download the latest version by opening the app and clicking “Check for Updates”.
You can join the discussion on ASUS’ security vulnerabilities on the OC3D Forums.
