Cisco Talos disclosed multiple high-severity vulnerabilities in the AsIO3.sys kernel driver used by ASUS Armoury Crate and related utilities, including an authorization bypass tracked as CVE-2025-3464. The bypass affects Armoury Crate versions 5.9.9.0 through 6.1.18.0 and lets a low-privileged authenticated attacker abuse a race condition and a specially crafted hard link to defeat the driver’s SHA-256-based validation of AsusCertService.exe, obtain access to the \Device\Asusgio3 device, and escalate privileges to SYSTEM. Talos said the exposed device functionality includes physical memory mapping, I/O port access, and MSR register access, creating a path to full system compromise.
Talos also reported a separate stack-based buffer overflow in the same driver family, affecting Armoury Crate 5.9.13.0, AI Suite 3 1.0.0.0, and AsIO3 Driver 1.02.30, where a path-conversion routine copies an application image path into a fixed-size stack buffer without proper length checks. A specially crafted long path can trigger stack corruption during handle acquisition for the Asusgio3 device, and Talos confirmed the condition with a DRIVER_OVERRAN_STACK_BUFFER bugcheck. ASUS has released patches for the issues and urged users and administrators to update affected software immediately.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos publicly released details of the AsIO3.sys stack-based buffer overflow vulnerability. The disclosure described how an unprivileged user-mode attacker could trigger stack corruption in the ASUS driver.
ASUS released a patch for the AsIO3.sys authorization bypass vulnerability, and Cisco Talos publicly disclosed the issue the same day. The flaw was later tracked as CVE-2025-3464 and affected Armoury Crate versions 5.9.9.0 through 6.1.18.0.
ASUS released a patch for the stack-based buffer overflow vulnerability in AsIO3.sys after Talos disclosure. The fix addressed a path-conversion routine that could overflow a fixed-size stack buffer during device handle acquisition.
Cisco Talos notified ASUS of an authorization bypass vulnerability in the AsIO3.sys driver used by Asus Armoury Crate 5.9.13.0. The issue allowed a low-privileged attacker to use a crafted hard link to bypass device access checks and potentially achieve full system compromise.
Cisco Talos reported a stack-based buffer overflow vulnerability in the AsIO3.sys kernel driver to ASUS and shared proof-of-concept code. The flaw affected Asus Armoury Crate 5.9.13.0, AI Suite 3 version 1.0.0.0, and AsIO3 Driver 1.02.30.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcetalosintelligence.com
Open sourcetalosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.