• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

ASUS Patches DriverHub RCE Flaws Exploitable through HTTP and Crafted .ini Information

Admin by Admin
May 13, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Could 12, 2025Ravie LakshmananVulnerability / Endpoint Safety

ASUS Patches DriverHub RCE Flaws

ASUS has launched updates to deal with two safety flaws impacting ASUS DriverHub that, if efficiently exploited, might allow an attacker to leverage the software program as a way to obtain distant code execution.

DriverHub is a software that is designed to robotically detect the motherboard mannequin of a pc and show crucial driver updates for subsequent set up by speaking with a devoted website hosted at “driverhub.asus[.]com.”

The issues recognized within the software program are listed beneath –

  • CVE-2025-3462 (CVSS rating: 8.4) – An origin validation error vulnerability that will permit unauthorized sources to work together with the software program’s options through crafted HTTP requests
  • CVE-2025-3463 (CVSS rating: 9.4) – An improper certificates validation vulnerability that will permit untrusted sources to have an effect on system conduct through crafted HTTP requests

Safety researcher MrBruh, who’s credited with discovering and reporting the 2 vulnerabilities, stated they might be exploited to attain distant code execution as a part of a one-click assault.

Cybersecurity

The assault chain basically includes tricking an unsuspecting consumer into visiting a sub-domain of driverhub.asus[.]com (e.g., driverhub.asus.com..com) after which leveraging the DriverHub’s UpdateApp endpoint to execute a respectable model of the “AsusSetup.exe” binary with an possibility set to run any file hosted on the pretend area.

“When executing AsusSetup.exe it first reads from AsusSetup.ini, which incorporates metadata in regards to the driver,” the researcher defined in a technical report.

“Should you run AsusSetup.exe with the -s flag (DriverHub calls it utilizing this to do a silent set up), it’s going to execute no matter is laid out in SilentInstallRun. On this case, the ini file specifies a cmd script that performs an automatic headless set up of the motive force, but it surely might run something.”

All an attacker must efficiently pull off the exploit is to create a site, and host three information, the malicious payload to be run, an altered model of AsusSetup.ini that has the “SilentInstallRun” property set to the malicious binary, and AsusSetup.exe, which then make use of the property to run the payload.

Following accountable disclosure on April 8, 2025, the problems had been fastened by ASUS on Could 9. There is no such thing as a proof that the vulnerabilities have been exploited within the wild.

“This replace consists of vital safety updates and ASUS strongly recommends that customers replace their ASUS DriverHub set up to the most recent model,” the corporate stated in a bulletin. “The most recent Software program Replace may be accessed by opening ASUS DriverHub, then clicking the ‘Replace Now’ button.”

Discovered this text fascinating? Observe us on Twitter  and LinkedIn to learn extra unique content material we submit.



Tags: .iniASUSCraftedDriverHubExploitableFilesFlawsHTTPPatchesRCE
Admin

Admin

Next Post
What Can You Do with a Free Semrush Account?

What Can You Do with a Free Semrush Account?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Xiaomi’s Latest Finances Android Telephone Is Solely Appropriate With This US Community

Xiaomi’s Latest Finances Android Telephone Is Solely Appropriate With This US Community

April 23, 2026
The Finest Mattress for Again Ache: 7 High Choices We Examined (2025)

The Finest Mattress for Again Ache: 7 High Choices We Examined (2025)

January 17, 2026

Trending.

The way to Clear up the Wall Puzzle in The place Winds Meet

The way to Clear up the Wall Puzzle in The place Winds Meet

November 16, 2025
Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

April 29, 2026
Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

April 21, 2026
Google DeepMind Introduces Decoupled DiLoCo: An Asynchronous Coaching Structure Reaching 88% Goodput Below Excessive {Hardware} Failure Charges

Google DeepMind Introduces Decoupled DiLoCo: An Asynchronous Coaching Structure Reaching 88% Goodput Below Excessive {Hardware} Failure Charges

April 24, 2026
5 AI Compute Architectures Each Engineer Ought to Know: CPUs, GPUs, TPUs, NPUs, and LPUs In contrast

5 AI Compute Architectures Each Engineer Ought to Know: CPUs, GPUs, TPUs, NPUs, and LPUs In contrast

April 10, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

A very powerful determination | Seth’s Weblog

Nostalgia could be deadly | Seth’s Weblog

May 2, 2026
Anthropic Opens Claude Safety for Wider Public

Anthropic Opens Claude Safety for Wider Public

May 2, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved