• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

ASUS Patches DriverHub RCE Flaws Exploitable through HTTP and Crafted .ini Information

Admin by Admin
May 13, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Could 12, 2025Ravie LakshmananVulnerability / Endpoint Safety

ASUS Patches DriverHub RCE Flaws

ASUS has launched updates to deal with two safety flaws impacting ASUS DriverHub that, if efficiently exploited, might allow an attacker to leverage the software program as a way to obtain distant code execution.

DriverHub is a software that is designed to robotically detect the motherboard mannequin of a pc and show crucial driver updates for subsequent set up by speaking with a devoted website hosted at “driverhub.asus[.]com.”

The issues recognized within the software program are listed beneath –

  • CVE-2025-3462 (CVSS rating: 8.4) – An origin validation error vulnerability that will permit unauthorized sources to work together with the software program’s options through crafted HTTP requests
  • CVE-2025-3463 (CVSS rating: 9.4) – An improper certificates validation vulnerability that will permit untrusted sources to have an effect on system conduct through crafted HTTP requests

Safety researcher MrBruh, who’s credited with discovering and reporting the 2 vulnerabilities, stated they might be exploited to attain distant code execution as a part of a one-click assault.

Cybersecurity

The assault chain basically includes tricking an unsuspecting consumer into visiting a sub-domain of driverhub.asus[.]com (e.g., driverhub.asus.com..com) after which leveraging the DriverHub’s UpdateApp endpoint to execute a respectable model of the “AsusSetup.exe” binary with an possibility set to run any file hosted on the pretend area.

“When executing AsusSetup.exe it first reads from AsusSetup.ini, which incorporates metadata in regards to the driver,” the researcher defined in a technical report.

“Should you run AsusSetup.exe with the -s flag (DriverHub calls it utilizing this to do a silent set up), it’s going to execute no matter is laid out in SilentInstallRun. On this case, the ini file specifies a cmd script that performs an automatic headless set up of the motive force, but it surely might run something.”

All an attacker must efficiently pull off the exploit is to create a site, and host three information, the malicious payload to be run, an altered model of AsusSetup.ini that has the “SilentInstallRun” property set to the malicious binary, and AsusSetup.exe, which then make use of the property to run the payload.

Following accountable disclosure on April 8, 2025, the problems had been fastened by ASUS on Could 9. There is no such thing as a proof that the vulnerabilities have been exploited within the wild.

“This replace consists of vital safety updates and ASUS strongly recommends that customers replace their ASUS DriverHub set up to the most recent model,” the corporate stated in a bulletin. “The most recent Software program Replace may be accessed by opening ASUS DriverHub, then clicking the ‘Replace Now’ button.”

Discovered this text fascinating? Observe us on Twitter  and LinkedIn to learn extra unique content material we submit.



Tags: .iniASUSCraftedDriverHubExploitableFilesFlawsHTTPPatchesRCE
Admin

Admin

Next Post
What Can You Do with a Free Semrush Account?

What Can You Do with a Free Semrush Account?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

How synthetic intelligence may also help obtain a clear power future | MIT Information

How synthetic intelligence may also help obtain a clear power future | MIT Information

November 29, 2025
Strengthening our Frontier Security Framework

Strengthening our Frontier Security Framework

September 23, 2025

Trending.

The way to Clear up the Wall Puzzle in The place Winds Meet

The way to Clear up the Wall Puzzle in The place Winds Meet

November 16, 2025
Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

April 29, 2026
Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

April 21, 2026
Google DeepMind Introduces Decoupled DiLoCo: An Asynchronous Coaching Structure Reaching 88% Goodput Below Excessive {Hardware} Failure Charges

Google DeepMind Introduces Decoupled DiLoCo: An Asynchronous Coaching Structure Reaching 88% Goodput Below Excessive {Hardware} Failure Charges

April 24, 2026
5 AI Compute Architectures Each Engineer Ought to Know: CPUs, GPUs, TPUs, NPUs, and LPUs In contrast

5 AI Compute Architectures Each Engineer Ought to Know: CPUs, GPUs, TPUs, NPUs, and LPUs In contrast

April 10, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

G2’s Evaluation of 500 Purchaser Opinions

G2’s Evaluation of 500 Purchaser Opinions

May 2, 2026
Musk v. Altman week 1: Elon Musk says he was duped, warns AI may kill us all, and admits that xAI distills OpenAI’s fashions

Musk v. Altman week 1: Elon Musk says he was duped, warns AI may kill us all, and admits that xAI distills OpenAI’s fashions

May 2, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved