CVE-2025-9968

HIGH

Armoury Crate - Privilege Escalation

Title source: llm
STIX 2.1

Description

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, please refer to section 'Security Update for Armoury Crate App' in the ASUS Security Advisory.

Scores

CVSS v4 8.5
EPSS 0.0002
EPSS Percentile 5.8%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (1)
ASUS/Armoury Crate before 6.3.4
Published Oct 13, 2025
Tracked Since Feb 18, 2026