CVE-2026-12962
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate Appย ' section on the ASUS Security Advisory for more information.
| CWE | CWE-942 |
| Vendor | asus |
| Product | armoury crate |
| Published | Sep 8, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for asus armoury crate
Be the first to know when new unknown vulnerabilities affecting asus armoury crate are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ASUS / Armoury Crate
0 โค 6.5.7.0