Security/ asus · bios · security · motherboards

Asus Fixes Local Exploit Flaw in Older Intel Motherboard BIOS

Asus patched a high severity flaw that let anyone with physical access to 13 older Z390 and workstation boards read or write arbitrary memory.

Asus has fixed a security flaw in the BIOS for a batch of its older Intel motherboards, and this time it is worth actually installing the update.

The bug, CVE-2026-93495, stems from improper initialization in the BIOS. It lets someone with physical access to the machine read or write arbitrary memory by plugging in a specially crafted device. Asus rates the issue 7.0 out of 10 and says it affects 13 boards built for 8th and 9th generation Intel chips, including several ROG Strix and Maximus XI models, the Prime Z390-A, the Pro WS C246-ACE, and the WS Z390 Pro. The company is urging owners to update to BIOS version 2203, or 1502 for the WS Z390 Pro.

Local-access vulnerabilities get waved off because an attacker needs to be in the room. That ignores how many of these boards live in offices, labs, repair shops, and secondhand sales, where a brief moment alone with a machine is not hard to arrange. BIOS-level compromises are also nastier than typical malware because they survive a fresh OS install and are invisible to most security software.

This is the second Asus firmware or software security bulletin in two months, after a high severity flaw in Armoury Crate surfaced in August. Two incidents is not a pattern yet, but it is a reason to actually check for updates instead of leaving that tab open indefinitely. These are six and seven year old boards at this point. Updating the BIOS is still the least fun item on anyone's to-do list, but it beats being the test case for a memory exploit.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →