Don't fear the BIOS update: Asus has just fixed a local access vulnerability affecting older Intel motherboards

7MMO

Moderator
I'll be honest: BIOS updates give me the willies. Unfortunately, even as such a source of undue anxiety, they are still well worth staying on top of. Case in point, the latest BIOS update from Asus addresses a vulnerability found in motherboards for 8th and 9th Gen Intel chips.

The vulnerability in question is described as "Improper initialization in an ASUS certain motherboard [sic] allows an physically proximate user to read or write arbitrary memory by inserting a specially crafted device." Basically, a bad actor would need to be in the same room as an affected PC to exploit this vulnerability. Even though local access is required, it's still a pretty serious issue.

Designated CVE-2026-93495, the issue has a high severity score of 7.0. As such, Asus has issued a security bulletin earlier today saying it "strongly recommends updating to the latest version" of the BIOS for a list of affected motherboards.


The affected motherboards include a number of ROG Strix and ROG Maximus models. I've included the full list of models, plus the fixed BIOS update that Asus recommends downloading, below:


Motherboard Model

Affected BIOS Version

Fixed BIOS Version

PRIME Z390-A

through 2101

2203

PRIME Z390-A/H10

through 2101

2203

ROG MAXIMUS XI HERO

through 2101

2203

ROG MAXIMUS XI HERO (WI-FI)

through 2101

2203

ROG MAXIMUS XI FORMULA

through 2101

2203

ROG MAXIMUS XI CODE

through 2101

2203

ROG MAXIMUS XI EXTREME

through 2101

2203

ROG MAXIMUS XI APEX

through 2101

2203

ROG MAXIMUS XI GENE

through 2101

2203

ROG STRIX Z390-E GAMING

through 2101

2203

ROG STRIX Z390-F GAMING

through 2101

2203

Pro WS C246-ACE

through 2101

2203

WS Z390 PRO

through 1401

1502

You can download the relevant updates from the Asus support site here. Asus also has a handy guide for how to update the BIOS in Windows here. Users of Asus Armory Crate and similar software tools may also want to make sure they're not missing out on any recent updates, as another high severity security vulnerability was discovered back in August.

Continue reading...
 
Back
Top