The Asus tool PC gamers use to update drivers, fix bugs, and improve security, turns out to have a bit of a security issue itself
Bug hunting.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
Driver updates—yes, I know they're not fun, but we've all got to do them. At the very least, they're somewhat less nerve-wracking than a BIOS update; I know I really should do those more often, too, but the thought of something going awry part-way through just makes me queasy. Asus at least has a driver tool called DriverHub to make things easier. Unfortunately, a recent Hub bug may have left the back door open to hackers.
If you've got an Asus motherboard or an otherwise prebuilt system, you should update DriverHub now, as your system may be at risk of a remote code execution attack (via Hot Hardware).
Simply put, DriverHub acts like an open network server in your machine, looking for HTTP requests and validating the ones that directly come from driverhub.asus.com. Unfortunately, if we think of DriverHub as a somewhat exclusive club, it needs to fire its bouncer as it will also let in driverhub.asus.com.but.with.funny.glasses.and.a.trenchcoat.com.
Turns out this driver tool is not as secure as anyone would like. If someone were to set up my aforementioned, creatively named domain, all they'd then need to do would be to upload a file containing a genuine Asus installer with administrator permissions alongside malicious files of their choice. This is because DriveHub only validates the digital signature of the installer, but none of the files that the executable is hoping to install on your system.
To deploy the club metaphor once more, DriveHub's bouncer waves in someone who is clearly not Asus, and then the security at bag check looks them over, goes, 'Yup, that's definitely a very fashionable trenchcoat,' but doesn't look in any of their pockets. The impostor then saunters towards the VIP room to make a royal mess that I definitely wouldn't want to be tasked with cleaning up.
Unfortunately, this party-crashing bug isn't as new or as surprising as some might hope. A security researcher going by the handle MrBruh recently detailed the vulnerability before disclosing it to Asus. However, it turns out the company may have known about the issue as early as February after another researcher, "leonjza", also brought it to their attention.
Still, the vulnerability was registered with NIST as CVE-2025-3462 and CVE-2025-3463 last week, and both have the dubious honour of a high CVSS-B score (8.4 and 9.4 respectively).
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
Thankfully, it's easy enough to update from within DriverHub itself. Alternatively, if you had already turned off automatic update installs directly within your BIOS, thereby likely avoiding the bug, you're allowed to feel just a bit smug.
As much as I'd rather put off BIOS updates—especially after writing about this ill-fated 100-hour update recently—I should probably get comfortable poking around in there myself. Turning off automatic installation might present a bit of a faff in the short term, but with Nvidia issuing GPU driver hotfixes to earlier hotfixes that also fail to fix, it might just be worth my while.
Best CPU for gaming: Top chips from Intel and AMD.
Best gaming motherboard: The right boards.
Best graphics card: Your perfect pixel-pusher awaits.
Best SSD for gaming: Get into the game first.

Jess has been writing about games for over ten years, spending the last seven working on print publications PLAY and Official PlayStation Magazine. When she’s not writing about all things hardware here, she’s getting cosy with a horror classic, ranting about a cult hit to a captive audience, or tinkering with some tabletop nonsense.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.


