CVE-2026-12962

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service endpoint.Refer to the ' Security Update for Armoury Crate AppĀ ' section on the ASUS Security Advisory for more information.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 03:17

Updated : 2026-09-08 14:03


NVD link : CVE-2026-12962

Mitre link : CVE-2026-12962

CVE.ORG link : CVE-2026-12962


JSON object : View

Products Affected

No product.

CWE
CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains