one click RCE in preinstalled ASUS garbage

one click RCE in preinstalled ASUS garbage

Source: YouTube · Low Level · published Jun 13, 2025 · 18:08

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

ASUS's DriverHub software contained a critical one-click remote code execution vulnerability due to insecure RPC implementation and weak origin checking 0:00-0:03.

Key Takeaways:
• DriverHub runs an insecure RPC service on localhost that only checks if "asus.com" is contained in the origin header, allowing easy bypass 4:54-5:54
• The update app endpoint could download and execute files with insufficient validation, enabling code execution 9:00-9:54
• RCE was achieved by exploiting the silent install feature in ASUS driver packages, which executes arbitrary commands specified in setup.ini files 11:49-12:52
• ASUS initially claimed the issue was limited to motherboards, but it actually affects any system with DriverHub installed 16:01-16:18
• ASUS took 9 days to fix after reporting, doesn't offer a bug bounty program, and initially failed to properly credit the researcher 13:03-14:11

The vulnerability highlights concerning security practices from a major hardware manufacturer, suggesting users should disable or remove ASUS's pre-installed software when possible.

Sources:

  • 0:00-0:03 Introduction to the one-click RCE vulnerability
  • 4:54-5:54 Explanation of the insecure origin check vulnerability
  • 9:00-9:54 Details of the update app endpoint vulnerability
  • 11:49-12:52 How RCE was achieved through silent install feature
  • 13:03-14:11 ASUS's response timeline and bug bounty program di

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

one-click rce in ASUS's pre-installed driver software. I saw this article. I had to read it. Uh primarily because two things. One, my motherboard fried a long time ago and it was ASUS and I'm still mad about it. But also two, I once again went out and bought another ASUS motherboard. So, I would like to know if there is a remote code execution vulnerability in the current setup that I have in my studio. Let's dive right in. Introduction. The story begins the conversation about PC parts, about new PC parts. I hope you're not getting it for the Wi-Fi. Not particularly. I'll be using the Wi-Fi though if needed. I don't know a lot about MOOs. After ignoring the advice from my friend, I bought a new ASUS motherboard for my PC. I was a little concerned about having a BIOS that would try to silen…