{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ai-suite/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2025-3464"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AsIO3.sys","Armoury Crate","AI Suite"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ASUS"],"content_html":"\u003cp\u003eCVE-2025-3464 is a local privilege escalation (LPE) vulnerability affecting the ASUS AsIO3.sys driver, a component often bundled with ASUS utilities such as Armoury Crate and AI Suite. The vulnerability stems from two primary flaws: a time-of-check time-of-use (TOCTOU) authentication bypass and an arbitrary 8-byte decrement primitive triggered via IOCTL 0xA0402450. Attackers can abuse these flaws to modify the KTHREAD structure of a running process, specifically toggling the 'PreviousMode' field from 1 (UserMode) to 0 (KernelMode). This transition grants the process the ability to perform arbitrary kernel-mode memory read/write operations. By manipulating the EPROCESS structure, a local unprivileged user can steal the SYSTEM token to achieve full administrative control over the host. The exploit is documented to work on Windows 11 22H2; newer Windows versions incorporate protections that render these specific PreviousMode manipulation techniques ineffective.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates an NTFS hardlink to a directory or file path containing the substring \u0026quot;AsusCertService\u0026quot;.\u003c/li\u003e\n\u003cli\u003eAttacker launches a controlled process (the exploit) through the created hardlink to bypass the driver's path validation check.\u003c/li\u003e\n\u003cli\u003eAttacker re-points the hardlink to the legitimate \u003ccode\u003eAsusCertService.exe\u003c/code\u003e to satisfy the driver's authentication requirements.\u003c/li\u003e\n\u003cli\u003eThe malicious process opens a handle to the \u003ccode\u003e\\\\.\\AsIO3\u003c/code\u003e device.\u003c/li\u003e\n\u003cli\u003eThe attacker invokes IOCTL 0xA0402450, triggering the vulnerable \u003ccode\u003eObfDereferenceObject\u003c/code\u003e function to decrement memory at a chosen address.\u003c/li\u003e\n\u003cli\u003eThe exploit targets the KTHREAD+0x232 field to set PreviousMode to 0, enabling kernel-mode access for the user-mode process.\u003c/li\u003e\n\u003cli\u003eAttacker performs token stealing by locating the SYSTEM EPROCESS structure and updating their own process token.\u003c/li\u003e\n\u003cli\u003eAttacker restores the PreviousMode to 1 to avoid system instability (BSOD) and executes a payload with SYSTEM privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full local privilege escalation to the NT AUTHORITY\\SYSTEM account. This allows an attacker who has already gained a low-privileged foothold on a Windows machine to gain total control over the operating system, bypass security controls, and persist with the highest level of system privileges. The scope is limited to systems where the vulnerable ASUS driver is installed and specifically on Windows 11 22H2 or older builds that lack modern protections against PreviousMode manipulation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit systems with the ASUS AsIO3.sys driver installed, particularly those running Windows 11 22H2 or older.\u003c/li\u003e\n\u003cli\u003eUninstall or update ASUS software (Armoury Crate, AI Suite) to versions that incorporate a patched version of the driver.\u003c/li\u003e\n\u003cli\u003eDeploy endpoint security policies to restrict the loading of vulnerable third-party drivers using Windows Defender Application Control (WDAC).\u003c/li\u003e\n\u003cli\u003eMonitor for processes attempting to access \u003ccode\u003e\\\\.\\AsIO3\u003c/code\u003e or making unexpected IOCTL calls to the driver.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T04:36:44Z","date_published":"2026-08-27T04:36:44Z","id":"https://feed.craftedsignal.io/briefs/2026-08-asio3-lpe/","summary":"An exploit for CVE-2025-3464 allows local attackers to escalate privileges to SYSTEM by leveraging a TOCTOU authentication bypass and an arbitrary decrement primitive within the ASUS AsIO3.sys driver.","title":"Local Privilege Escalation in ASUS AsIO3.sys Driver (CVE-2025-3464)","url":"https://feed.craftedsignal.io/briefs/2026-08-asio3-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - AI Suite","version":"https://jsonfeed.org/version/1.1"}