CVE-2026-3428 Details
Description
A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a Time-of-check Time-of-use (TOC-TOU) during the update process, where an unexpected payload is substituted for a legitimate one immediately after download, and subsequently executed with administrative privileges upon user consent. Refer to the 'Security Update for ASUS Member Center' section on the ASUS Security Advisory for more information.
A vulnerability allowing privilege escalation to Administrator has been identified in the update modules of ASUS Member Center, versions through 1.6.6.4. This vulnerability arises from a download of code without integrity checks, exploiting a Time-of-check Time-of-use (TOC-TOU) issue during the update process. A local user can substitute an unexpected payload for a legitimate one immediately after download, which is then executed with administrative privileges upon user consent.
Users can refer to the 'Security Update for ASUS Member Center' section on the ASUS Security Advisory for update instructions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.asus.com/security-advisory/ | ASUS |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | ASUS |
| CWE-494 | Download of Code Without Integrity Check | ASUS |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ASUS |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | New CVE Received | ASUS |