CVE-2026-8917Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an arbitrary memory address, potentially leading to privilege escalation. Refer to the '  Security Update for ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and Armoury Crate Security Bulletin   ' section on the ASUS Security Advisory for more information.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-822

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-08-11); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-08-11: 4Mentions · 2026-08-13: 1Mentions · 2026-08-15: 1Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-15: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-13: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-17: 108-1108-1308-1508-17
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-114
Disclosure3General1
2026-08-131
Patch1
2026-08-151
Patch1
2026-08-171
Disclosure1
Full discourse7 posts
  • Angelo@lem0nSec_
    Disclosure

    Happy to share that a vulnerability I discovered has been assigned CVE-2026-8917. An untrusted pointer dereference affecting ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, Armoury Crate. The CVSS score is 8.4 High. More details at https://www.cve.org/CVERecord?id=CVE-2026-8917

    Post summary

    A new vulnerability (CVE‑2026‑8917) affecting ASUS GPU Tweak and related applications has been identified as an untrusted pointer dereference with a CVSS score of 8.4. No PoC, exploit, patch, or active exploitation details are mentioned.

    0001073
    23 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    CyberSec Daily ✓ · 💻 Hardware Security · August 15, 2026 🎯 ASUS users should update Armoury Crate and related utilities CVE-2026-8917 is a high-severity local privilege-escalation vulnerability affecting components used by several ASUS utilities. Affected software reportedly includes GPU Tweak and AI Suite components, with ASUS also advising Armoury Crate users to update. Hardware-management utilities should not be ignored during patching. 🔗 Sources: ASUS Security Advisory / PC Gamer report #ASUS #ArmouryCrate #CVE20268917 #PrivilegeEscalation #EndpointSecurity

    Post summary

    The advisory announces CVE‑2026‑8917, a high‑severity local privilege‑escalation flaw in ASUS utilities, and urges users to update Armoury Crate and related software to mitigate the risk.

    0001049
    58 followersView on X
  • Baldly Rudy@baldlyrudy
    Patch

    ASUS users should update Armoury Crate. A new high-severity vulnerability, CVE-2026-8917, affects several ASUS utilities and a component used by Armoury Crate. -CVSS 8.4 / High -Could allow local privilege escalation -Affects GPU Tweak III / II + AI Suite 3 -Also affects VGAdll used by Armoury Crate ASUS recommends updating immediately Relevant for ROG laptops, desktops + handhelds running Armoury Crate.

    Post summary

    CVE-2026-8917 is a high‑severity local privilege escalation flaw affecting ASUS utilities; ASUS advises users to apply the available update immediately.

    10000190
    1.1K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Asus ❗ CVE-2026-8917 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-asus-4/ https://t.co/VILJNoan5E

    Post summary

    The post announces a new vulnerability (CVE-2026-8917) affecting Asus products and points to external links for additional details.

    00000187
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8917 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an a… https://www.cve.org/CVERecord?id=CVE-2026-8917 ----- Traducción: CVE-2026-8917 Des… http://infoflow.cloud`

    Post summary

    The tweet announces the vulnerability CVE-2026‑8917 with a concise technical description and a link to the CVE record, containing no evidence of exploitation or mitigation.

    0000037
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8917 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a specific value to an a… https://www.cve.org/CVERecord?id=CVE-2026-8917

    Post summary

    The text announces CVE‑2026‑8917, describing it as an IOCTL‑based untrusted pointer dereference that lets a local attacker write a value. No PoC, exploit, patch, or evidence of active exploitation is mentioned.

    00000667
    57.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8917 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8917

    Post summary

    The content briefly describes CVE‑2026‑8917 as an untrusted pointer dereference affecting ASUS GPU tools, with no further details on PoC, exploitation, patching, or false positives.

    00000151
    4.1K followersView on X

Explore more