June 16, 2025 By Bill Toulas

A high-severity vulnerability in ASUS Armoury Crate software could allow threat actors to escalate their privileges to SYSTEM level on Windows machines.
The security issue is tracked as CVE-2025-3464 and received a severity score of 8.8 out of 10.
It could be exploited to bypass authorization and affects the AsIO3.sys of the Armoury Crate system management software.
Armoury Crate is the official system control software for Windows from ASUS, providing a centralized interface to control RGB lighting (Aura Sync), adjust fan curves, manage performance profiles and ASUS peripherals, as well as download drivers and firmware updates.
To perform all these functions and provide low-level system monitoring, the software suite uses the kernel driver to access and control hardware features.