ASUS Updates Security Certificates of Motherboards, Graphics Cards, Mini PCs, Workstations

Published by

teaser

ASUS is releasing this advisory to provide information related to the new implementation of a tiered certificate structure that upgrades the security infrastructure of our expanding software ecosystem. 



The upgrade requires the current code-signing certificate of several ASUS products to be revoked. This revocation can cause some existing software utilities to trigger a Windows Security dialog box, and may prevent legitimate ASUS programs, such as Aura, AI Suite III, GPU Tweak II and others, from running normally when users attempt to execute the associated 'Setup.exe' or 'AsusSetup.exe' file.

The new versions of each ASUS software update, code-signed with a new digital certificate are now available for download at the link provided below. Once the latest version of the respective software is downloaded, the relevant program can be installed and run normally. Further information can be found in the Advisory FAQ section below. Users who have any inquiries or concerns are welcome to contact ASUS Customer Service. ASUS apologizes for any inconvenience caused by this update.

Updated Software List
Download links for each software program can be found here.

Advisory FAQ
What is a code-signing certificate?

Many companies, including ASUS, use electronic certificates to digitally 'sign' software code. These unique signatures provide users with an assurance that the code is legitimate, and has not been modified since being signed by the developer.

For more information, please follow the link below: https://www.digicert.com/blog/ms-smartscreen-application-reputation/
Is my current ASUS software safe to use?

Yes. All previously released ASUS software obtained from official sources, such as the official ASUS support website, ASUS Q-Installer, ASUS Armoury Crate, or an ASUS support CD, is safe and does not contain any malicious code. However, to account for the growth of our software ecosystem, we have implemented a new certificate infrastructure that requires a software update. Please use the links above to download the latest software for your system.


How does this affect me as a user?
You may encounter one of four different scenarios:
Scenario 1: ASUS software (such as Aura, AI Suite III, GPU Tweak II etc.)

Because the aforementioned software operates at the driver and service level, Windows may perform regular checks on the validity of the certificate when trying to run the program normally. Once the certificate has been revoked, Windows may prevent you from running the program altogether. In this case, you will need to download the newest code-signed version from the support page link listed above.


Scenario 2: Third-party drivers and software packed with ASUS products
The source code for third-party drivers and software are not produced by ASUS. As such, they will be code-signed by the third-party provider, and therefore are not affected by the revocation of the ASUS certificate. If you have existing drivers installed, you can continue to use them safely.
However, if you are trying to install third-party drivers or software from an ASUS support CD then you may still encounter a warning dialog. This is because the ASUS support CD provides a setup file called 'AsusSetup.exe' that may act as a shortcut to a 'Setup.exe' file created by a third-party provider. Because 'AsusSetup.exe' is code-signed by ASUS, you may encounter a warning message preventing you from proceeding with installation.
To proceed, either download the latest code-signed drivers from the support page link listed above or directly execute the third-party provider's 'Setup.exe' file - as this will bypass the ASUS installation program - 'AsusSetup.exe'.


Scenario 3: Running an ASUS support CD
Windows may prevent you from running an ASUS support CD normally. Please use the links provided in this advisory notice to download the latest versions of the appropriate program files for your ASUS product.


Scenario 4: Starting (booting) your PC
this question is dedicated for motherboards with Armoury Crate or Q-installer
After starting (booting) your PC for the first time, you may encounter a warning message preventing you from installing and running ASUS Armoury Crate. If this occurs you will need to update the BIOS to the latest version or disable this feature.
You can access the BIOS and disable this feature to prevent this message from continually popping up. To do this, first restart your PC, and then press the Delete (Del) or F2 key when prompted during the startup process. Now navigate to the 'Tools' tab and then select the 'ASUS Armoury Crate' category. Then choose the 'Disable the Download & Install ARMOURY CRATE app' option. To save these changes and restart the system, press the F10 key, then press Y when prompted. Alternatively, navigate to the 'Save and Exit' option within the BIOS menu, press the Enter key, then press Y to save changes and restart.

How do I uninstall previous versions of Aura, AI Suite III, and LiveDash?
Windows may prevent you from uninstalling the related software due to the revoked certificates. In order to uninstall these programs, you will first have to disable Microsoft's User Account Control (UAC):

  • Type UAC in the search field of the Windows taskbar. (If the search field isn't visible, for Windows 10, right-click the Start button and choose Search; for Windows 7, left-click the Start button and choose Search)
  • Click 'Change User Account Control settings' in the search results.
  • To turn UAC off, drag the slider down to 'Never notify' and then click 'OK'.
  • You may be prompted to confirm your selection or enter an administrator password.
  • Reboot your computer for the change to take effect.

After disabling UAC, you can proceed with uninstallation. Remember to reset UAC settings to the previous level after the uninstallation completes.


Share this content
Twitter Facebook Reddit WhatsApp Email Print