Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Gartner: Why neoclouds are the future of GPU-as-a-Service

    Runlayer is now offering secure OpenClaw agentic capabilities for large enterprises

    Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      Gartner: Why neoclouds are the future of GPU-as-a-Service

      February 21, 2026

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026
    • Crypto

      Another European Country Bans Polymarket, Threatens Massive Fine

      February 20, 2026

      Why Is The US Stock Market Up Today?

      February 20, 2026

      Is XRP Price Preparing To Breach Its 2026 Downtrend? Here’s What History Says

      February 20, 2026

      “Disgrace” or “Win for American Wallets”? Supreme Court Tariff Bombshell Sparks Political Meltdown in Washington

      February 20, 2026

      Perle Labs CEO Ahmed Rashad on Why AI Needs Verifiable Data Infrastructure

      February 20, 2026
    • Technology

      Runlayer is now offering secure OpenClaw agentic capabilities for large enterprises

      February 21, 2026

      Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

      February 21, 2026

      Be Wary of Bluesky

      February 21, 2026

      CERN rebuilt the original browser from 1989

      February 21, 2026

      Across the US, people are dismantling and destroying Flock surveillance cameras

      February 21, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»ASUS DriverHub flaw let malicious sites run commands with admin rights
    Technology

    ASUS DriverHub flaw let malicious sites run commands with admin rights

    TechAiVerseBy TechAiVerseMay 13, 2025No Comments4 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    ASUS DriverHub flaw let malicious sites run commands with admin rights
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    ASUS DriverHub flaw let malicious sites run commands with admin rights

    The ASUS DriverHub driver management utility was vulnerable to a critical remote code execution flaw that allowed malicious sites to execute commands on devices with the software installed.

    The flaw was discovered by an independent cybersecurity researcher from New Zealand named Paul (aka “MrBruh“), who found that the software had poor validation of commands sent to the DriverHub background service.

    This allowed the researcher to create an exploit chain utilizing flaws tracked as CVE-2025-3462 and CVE-2025-3463 that, when combined, achieve origin bypass and trigger remote code execution on the target.

    The DriverHub problem

    DriverHub is ASUS’s official driver management tool that is automatically installed on the first system boot when utilizing certain ASUS motherboards.

    This software runs in the background, automatically detecting and fetching the latest driver versions for the detected motherboard model and its chipset.

    Once installed, the tool remains active and running in the background via a local service on port 53000, continually checking for important driver updates.

    Meanwhile, most users don’t even know such a service is constantly running on their system.

    That service checks the Origin Header of incoming HTTP requests to reject anything that doesn’t come from ‘driverhub.asus.com.’

    However, this check is poorly implemented, as any site that includes that string is accepted even if it’s not an exact match to ASUS’s official portal.

    The second issue lies in the UpdateApp endpoint, which allows DriverHub to download and run .exe files from “.asus.com” URLs without user confirmation.

    The BIOS setting concerning DriverHub (Enabled by default)
    Source: MrBruh

    Stealthy attack flow

    An attacker can target any user with ASUS DriverHub running on their system to trick them into visiting a malicious website on their browser. This website then sends “UpdateApp requests” to the local service at ‘http://127.0.0.1:53000.’

    By spoofing the Origin Header to something like ‘driverhub.asus.com.mrbruh.com,’ the weak validation check is bypassed, so DriverHub accepts the commands.

    In the researcher’s demonstration, the commands order the software to download a legitimate ASUS-signed ‘AsusSetup.exe’ installer from the vendor’s download portal, along with a malicious .ini file and .exe payload.

    The ASUS-signed installer is silently run as admin and uses the configuration information in the .ini file. This ini file directs the legitimate ASUS driver installer to launch the malicious executable file.

    The attack is also made possible by the tool failing to delete files that fail signature checks, like the .ini and payload, which are kept on the host after their download.

    ASUS’ response and user action

    ASUS received the researcher’s reports on April 8, 2025, and implemented a fix on April 18, after validating it with MrBruh the day before. The hardware giant did not offer the researcher any bounty for his disclosure.

    The CVE descriptions, which the Taiwanese vendor submitted, somewhat downplays the issue with the following statement: 

    “This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints,” reads the CVE description.

    This is confusing, as the mentioned CVEs impact laptops and desktop computers with DriverHub installed.

    However, ASUS is clearer in its security bulletin, advising users to quickly apply the latest update. 

    “This update includes important security updates and ASUS strongly recommends that users update their ASUS DriverHub installation to the latest version,” reads the bulletin.

    “The latest Software Update can be accessed by opening ASUS DriverHub, then clicking the “Update Now” button.”

    MrBruh says he monitored certificate transparency updates and found no other TLS certificates containing the “driverhub.asus.com” string, indicating it was not exploited in the wild.

    If you’re uncomfortable with a background service automatically fetching potentially dangerous files upon visiting websites, you may disable DriverHub from your BIOS settings.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleWindows 11 upgrade block lifted after Safe Exam Browser fix
    Next Article It looks as though Garmin is working on another high-end smartwatch as a Fenix 8 spin-off
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Runlayer is now offering secure OpenClaw agentic capabilities for large enterprises

    February 21, 2026

    Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

    February 21, 2026

    Be Wary of Bluesky

    February 21, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025684 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025276 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025158 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025119 Views
    Don't Miss
    Business Technology February 21, 2026

    Gartner: Why neoclouds are the future of GPU-as-a-Service

    Gartner: Why neoclouds are the future of GPU-as-a-Service Neoclouds are set to change the economcs…

    Runlayer is now offering secure OpenClaw agentic capabilities for large enterprises

    Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

    Be Wary of Bluesky

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Gartner: Why neoclouds are the future of GPU-as-a-Service

    February 21, 20262 Views

    Runlayer is now offering secure OpenClaw agentic capabilities for large enterprises

    February 21, 20260 Views

    Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

    February 21, 20260 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.