logo

Decrement by one to rule them all: AsIO3.sys driver exploitation

ID: f8f4f84b-d2e0-5760-90b5-514f33902636

STIX ID: report--f8f4f84b-d2e0-5760-90b5-514f33902636

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2025-06-26

Date Updated: 2026-04-27

Author: Marcin Noga

...
...

This report details Talos's discovery and exploitation of critical vulnerabilities in the ASUS AsIO3.sys driver used by Armoury Crate: a stack-based buffer overflow in Win32-to-NT path conversion and an image-hash based authorization bypass. The researcher builds a local PoC exploit that achieves NT SYSTEM privileges by abusing a hardlink trick to pass the driver’s image-hash check, using an ObfDereferenceObject-based primitive to change a thread's PreviousMode, reading kernel memory to locate SYSTEM's EPROCESS and swapping its token; mitigations in Windows 11 24H2 limit some information leaks but the driver weaknesses remain high-risk for affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.