Several ASUS software tools should be updated as soon as possible for “optimal protection” following the discovery of a new security vulnerability, according to a public security bulletin. You can read more about the bulletin on the ASUS Security Portal or in the CVE record (CVE-2026-8917). The tools affected are ASUS GPU Tweak III, GPU Tweak II, AI Suite3 and VGAdll, a component “used by” Armory Crate. For those who don’t know or use these tools, ASUS Armory Crate is a system application for managing branded PCs and internal components, such as those included in ROG and TUF laptops or gaming systems. The other tools mentioned do something similar; GPU Tweak III is a tuning tool for ASUS GPUs.
CVE rates the vulnerability as high severity with a score of 8.4 out of 10, so you probably won’t want to avoid updating for too long if you’re using the toolset. If exploited, this issue “could allow a local user to escalate their privileges on the system”, which would likely enable some pretty nasty things if nefarious individuals were involved. You can update by downloading the latest packages from the ASUS support page. You can type the name of the software tool you need into the search bar and then select it as a product, such as “Armoury Crate”.
This is not the first time vulnerabilities have been discovered in Armory Crate. It’s worth mentioning that, depending on your computer’s hardware, there are many alternatives if you want a tool that does the same thing. G-Helper is for example a lightweight and open source alternative. You can use other tools like OpenRGB for lighting or Fan Control to adjust fans. However, compatibility differs from system to system.
ASUS has patched similar vulnerabilities in the past
As mentioned, ASUS has previously updated the same software tools when vulnerabilities have been discovered, such as Armory Crate alongside its other offerings. You can easily find several examples in the ASUS Security Advisory hub; However, July 2025 saw a particularly significant response from the support team. Meanwhile, ASUS has fixed issues in various routers and its software tools such as MyASUS, DriverHub and Armory Crate.
Despite these findings, ASUS is quite proactive in ensuring the security of its software tools. This continued support is one of the reasons why owners say that high-end ASUS laptops tend to last and are quite reliable. ASUS isn’t the only company to handle things this way. MSI also publishes product security advisories, and Lenovo and Dell do the same for broad computing categories, including commercial systems.
But who is pulling the strings for ASUS in particular? The company is based in Taiwan and, unlike some of its larger competitors, is not owned by a single parent company, but is publicly traded under ASUSTek Computer Inc., not to be confused with Acer, which is a completely different brand. You might be surprised to learn what the name “Asus” means and where it comes from. Of course I was. This is a shortened version of “Pegasus”, the mystical winged horse of Greek legend.
