HomeTechnologyIndian government warns of multiple security flaws in motherboards from ASRock, Gigabyte, MSI and others powering millions of Windows PCs

Indian government warns of multiple security flaws in motherboards from ASRock, Gigabyte, MSI and others powering millions of Windows PCs

India’s cybersecurity agency has flagged serious motherboard vulnerabilities that could allow attackers with physical access to bypass protections on Windows PCs, urging users and organisations to install vendor updates.

December 26, 2025 / 13:54 IST
Story continues below Advertisement
motherboard
motherboard

The Indian government has issued a cybersecurity warning highlighting multiple security flaws affecting popular PC motherboards used in millions of Windows systems across the country. The advisory has been released by CERT-In under the Ministry of Electronics and Information Technology, flagging risks linked to early boot-stage protections.

According to the advisory, the vulnerabilities could be exploited to bypass security restrictions and compromise system integrity, particularly in scenarios involving physical access to affected devices.

Story continues below Advertisement

Motherboard vendors and platforms affected
The vulnerabilities impact motherboards from several major manufacturers widely used in consumer and enterprise PCs. CERT-In listed affected platforms from ASRock, Gigabyte, MSI, along with ASUS and AMD-based boards used across different Intel and AMD chipset generations.
The affected systems primarily include motherboards paired with Intel 500, 600, 700 and 800 series chipsets, as well as several AMD chipset-based platforms. These boards are commonly found in desktops running Microsoft Windows across home, business and institutional environments.

What is the security risk?
CERT-In noted that the issue stems from improper enforcement of Direct Memory Access (DMA) protections during the early boot process. This weakness could allow a local attacker with physical access to connect a malicious PCIe device and gain unauthorised access to system memory before the operating system fully loads.