
🧰 CVE‑2026‑3428 – ASUS Member Center local priv‑esc (Info→High): In ASUS Member Center update modules, a TOC‑TOU flaw in the download‑and‑execute flow lets a local attacker swap the downloaded updater binary with a malicious payload right after download, which is then executed with Administrator privileges during the update. CVSS (v3.1) pending, NVD published 2026‑04‑16; fix available via ASUS Member Center security update. https://nvd.nist.gov/vuln/detail/CVE-2026-3428 #CVE20263428 #ASUS #PrivilegeEscalation #Windows #EndpointSecurity #ThreatIntel
Post summary
The tweet announces a local privilege escalation vulnerability (CVE‑2026‑3428) in ASUS Member Center, highlights the specific TOC‑TOU flaw, and confirms that a vendor update is available to address the issue.

