• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

ASUS Patches DriverHub RCE Flaws Exploitable through HTTP and Crafted .ini Information

Admin by Admin
May 13, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Could 12, 2025Ravie LakshmananVulnerability / Endpoint Safety

ASUS Patches DriverHub RCE Flaws

ASUS has launched updates to deal with two safety flaws impacting ASUS DriverHub that, if efficiently exploited, might allow an attacker to leverage the software program as a way to obtain distant code execution.

DriverHub is a software that is designed to robotically detect the motherboard mannequin of a pc and show crucial driver updates for subsequent set up by speaking with a devoted website hosted at “driverhub.asus[.]com.”

The issues recognized within the software program are listed beneath –

  • CVE-2025-3462 (CVSS rating: 8.4) – An origin validation error vulnerability that will permit unauthorized sources to work together with the software program’s options through crafted HTTP requests
  • CVE-2025-3463 (CVSS rating: 9.4) – An improper certificates validation vulnerability that will permit untrusted sources to have an effect on system conduct through crafted HTTP requests

Safety researcher MrBruh, who’s credited with discovering and reporting the 2 vulnerabilities, stated they might be exploited to attain distant code execution as a part of a one-click assault.

Cybersecurity

The assault chain basically includes tricking an unsuspecting consumer into visiting a sub-domain of driverhub.asus[.]com (e.g., driverhub.asus.com..com) after which leveraging the DriverHub’s UpdateApp endpoint to execute a respectable model of the “AsusSetup.exe” binary with an possibility set to run any file hosted on the pretend area.

“When executing AsusSetup.exe it first reads from AsusSetup.ini, which incorporates metadata in regards to the driver,” the researcher defined in a technical report.

“Should you run AsusSetup.exe with the -s flag (DriverHub calls it utilizing this to do a silent set up), it’s going to execute no matter is laid out in SilentInstallRun. On this case, the ini file specifies a cmd script that performs an automatic headless set up of the motive force, but it surely might run something.”

All an attacker must efficiently pull off the exploit is to create a site, and host three information, the malicious payload to be run, an altered model of AsusSetup.ini that has the “SilentInstallRun” property set to the malicious binary, and AsusSetup.exe, which then make use of the property to run the payload.

Following accountable disclosure on April 8, 2025, the problems had been fastened by ASUS on Could 9. There is no such thing as a proof that the vulnerabilities have been exploited within the wild.

“This replace consists of vital safety updates and ASUS strongly recommends that customers replace their ASUS DriverHub set up to the most recent model,” the corporate stated in a bulletin. “The most recent Software program Replace may be accessed by opening ASUS DriverHub, then clicking the ‘Replace Now’ button.”

Discovered this text fascinating? Observe us on Twitter  and LinkedIn to learn extra unique content material we submit.



Tags: .iniASUSCraftedDriverHubExploitableFilesFlawsHTTPPatchesRCE
Admin

Admin

Next Post
What Can You Do with a Free Semrush Account?

What Can You Do with a Free Semrush Account?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

77 Malicious Android Apps With 19M Installs Focused 831 Banks Worldwide

77 Malicious Android Apps With 19M Installs Focused 831 Banks Worldwide

August 26, 2025
Now It’s Claude’s World: How Anthropic Overtook OpenAI within the Enterprise AI Race

Now It’s Claude’s World: How Anthropic Overtook OpenAI within the Enterprise AI Race

August 4, 2025

Trending.

Microsoft Launched VibeVoice-1.5B: An Open-Supply Textual content-to-Speech Mannequin that may Synthesize as much as 90 Minutes of Speech with 4 Distinct Audio system

Microsoft Launched VibeVoice-1.5B: An Open-Supply Textual content-to-Speech Mannequin that may Synthesize as much as 90 Minutes of Speech with 4 Distinct Audio system

August 25, 2025
New Assault Makes use of Home windows Shortcut Information to Set up REMCOS Backdoor

New Assault Makes use of Home windows Shortcut Information to Set up REMCOS Backdoor

August 3, 2025
Begin constructing with Gemini 2.0 Flash and Flash-Lite

Begin constructing with Gemini 2.0 Flash and Flash-Lite

April 14, 2025
The most effective methods to take notes for Blue Prince, from Blue Prince followers

The most effective methods to take notes for Blue Prince, from Blue Prince followers

April 20, 2025
Stealth Syscall Method Permits Hackers to Evade Occasion Tracing and EDR Detection

Stealth Syscall Method Permits Hackers to Evade Occasion Tracing and EDR Detection

June 2, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Learn how to Watch ‘Survivor’: Stream Season 49 With out Cable

Learn how to Watch ‘Survivor’: Stream Season 49 With out Cable

September 22, 2025
Watch The Sims 4 Journey Awaits gameplay right here

Watch The Sims 4 Journey Awaits gameplay right here

September 22, 2025
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved