ASUS disclosed a high-severity vulnerability tracked as CVE-2026-8917 affecting multiple Windows utilities, including GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll. The flaw stems from an untrusted pointer dereference in an IOCTL handler that can let a local attacker write a specific value to an arbitrary memory address, creating a path to privilege escalation on affected systems.
The issue carries a CVSS 4.0 score of 8.4 and is classified under CWE-822. While the vulnerability is not remotely exploitable, national CERT notices and the CVE entry point users to ASUS security advisories and patched software versions as the primary mitigation, making updates a priority for organizations running the affected ASUS management and tuning tools.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CERT-PY published another notice concerning vulnerabilities in ASUS products. The reference shows a separate advisory publication tied to the same ASUS vulnerability story.
A CVE record was published for CVE-2026-8917, a high-severity arbitrary memory write vulnerability caused by an untrusted pointer dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll. The flaw can allow a local attacker to write a specific value to an arbitrary memory address and potentially escalate privileges.
CERT-PY published a notice about vulnerabilities affecting ASUS products. The reference indicates this was a distinct advisory publication related to the ASUS issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourcecvefeed.io
Open sourcecert.gov.py
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.