ASUS patched two vulnerabilities in its preinstalled DriverHub software that can be chained to achieve unauthenticated remote code execution on affected Windows systems. The flaws, tracked as CVE-2025-3462 and CVE-2025-3463, affect DriverHub versions earlier than 1.0.6.0 and stem from insufficient certificate and origin validation in the utility’s update and installation workflow. Researchers reported that the bugs allow a malicious website to interact with DriverHub through specially crafted HTTP requests and trigger code execution with minimal user interaction.
According to public reporting and ASUS’s security advisory, the attack abuses a driverhub.asus.com.<arbitrary>.com-style domain to pass validation checks, causing DriverHub to launch AsusSetup.exe in silent mode and process a malicious AsusSetup.ini file that redirects installation to attacker-controlled code. CSIRT.SK said successful exploitation could fully compromise the confidentiality, integrity, and availability of a victim machine. ASUS has released updates and urged users to upgrade DriverHub immediately to version 1.0.6.0 or later.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
ASUS released security updates for ASUS DriverHub to fix two vulnerabilities, including a critical flaw, affecting versions earlier than 1.0.6.0. The issues, tracked as CVE-2025-3462 and CVE-2025-3463, could be chained for remote code execution and ASUS recommended upgrading to version 1.0.6.0.
CSIRT.SK published a summary describing the ASUS DriverHub flaws as enabling remote unauthenticated compromise via insufficient certificate and origin validation, crafted HTTP requests, and user interaction with a malicious website. The write-up noted the attack could trigger AsusSetup.exe in silent mode and process a malicious AsusSetup.ini file to run attacker-controlled code.
A researcher published details of a one-click remote code execution issue in ASUS's preinstalled DriverHub software. The disclosure described how the flaws could be exploited through a malicious website targeting DriverHub's update-related behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcemrbruh.com
Open sourceasus.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.