Tech

A key Asus Windows tool has a worrying security flaw – here’s how to stay safe

Share
Share


  • Asus released a patch for CVE-2025-3464, a high-severity authentication bypass flaw
  • The issue affects Armoury Crate, a centralized hub for managing ASUS and ROG hardware
  • The flaw could possibly lead to full device takeover

Asus says it has fixed a high-severity vulnerability that could have allowed threat actors to bypass authentication requirements and obtain SYSTEM privileges on a Windows device.

Recently, a security researcher from Cisco Talos discovered an Armoury Crate kernel-mode driver doesn’t rely on proper OS-level checks, but instead authenticates requests using a hardcoded SHA-256 hash of AsusCertServices.exe and a PID allowlist.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
New system reliably controls prosthetic hand movements without relying on biological signals
Tech

New system reliably controls prosthetic hand movements without relying on biological signals

The autonomous prosthetic hand grasping a bottle using vision and touch sensors....

Salesforce raises prices on Slack and more, promises more AI integration as a result
Tech

Salesforce raises prices on Slack and more, promises more AI integration as a result

Salesforce Enterprise and Unlimited SKUs are going up by 6% on average...

Donkey Kong Bananza Direct live build-up: our predictions and all the key details ahead of the next Nintendo stream
Tech

Donkey Kong Bananza Direct live build-up: our predictions and all the key details ahead of the next Nintendo stream

Refresh 2025-06-18T11:39:46.507Z How about some unfiltered gameplay Donkey Kong Bananza – Gameplay...

Windows 11’s new Start menu falls short in one key area – and it’s making people angry
Tech

Windows 11’s new Start menu falls short in one key area – and it’s making people angry

Microsoft has a Start menu redesign in testing This introduces new layouts...