Tag: ASUS

New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards
News

New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards

A security flaw in some motherboard models from manufacturers such as ASRock, ASUSTeK Computer, GIGABYTE, and MSI makes them vulnerable to early-boot direct memory access (DMA) attacks in architectures that use input-output memory management units (IOMMU) and Unified Extensible Firmware Interface (UEFI). DMA-capable devices can change or examine system memory prior to the loading of the operating system since UEFI and IOMMU are built to impose a security foundation and stop peripherals from executing illegal memory accesses. A difference in the DMA protection state is the cause of the vulnerability, which was found in some UEFI implementations by Nick Peterson and Mohamed Al-Sharifi of Riot Games. The firmware fails to setup and activate the IOMMU at the crucial startup step, even i...
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
News

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed a significant vulnerability affecting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) database on Wednesday. The vulnerability, identified as CVE-2025-59374 (CVSS score: 9.3), has been characterized as an embedded malicious code vulnerability that was introduced through a supply chain compromise and may enable attackers to carry out unexpected operations. A description of the vulnerability released on CVE.org states that some versions of the ASUS Live Update client were issued with unauthorized modifications introduced through a supply chain hack. "Devices that meet certain targeting conditions may behave inadvertently as a result of the updated builds. The h...