CVE-2026-3428Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a Time-of-check Time-of-use (TOC-TOU) during the update process, where an unexpected payload is substituted for a legitimate one immediately after download, and subsequently executed with administrative privileges upon user consent. Refer to the 'Security Update for ASUS Member Center' section on the ASUS Security Advisory for more information.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367CWE-494

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-16: 2Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 204-16
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🧰 CVE‑2026‑3428 – ASUS Member Center local priv‑esc (Info→High): In ASUS Member Center update modules, a TOC‑TOU flaw in the download‑and‑execute flow lets a local attacker swap the downloaded updater binary with a malicious payload right after download, which is then executed with Administrator privileges during the update. CVSS (v3.1) pending, NVD published 2026‑04‑16; fix available via ASUS Member Center security update. https://nvd.nist.gov/vuln/detail/CVE-2026-3428 #CVE20263428 #ASUS #PrivilegeEscalation #Windows #EndpointSecurity #ThreatIntel

    Post summary

    The tweet announces a local privilege escalation vulnerability (CVE‑2026‑3428) in ASUS Member Center, highlights the specific TOC‑TOU flaw, and confirms that a vendor update is available to address the issue.

    0001027
    855 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3428 A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Admini… https://www.cve.org/CVERecord?id=CVE-2026-3428

    Post summary

    CVE-2026-3428 reveals a local privilege‑escalation flaw in ASUS Member Center’s update modules due to lack of integrity checks during code downloads.

    0000080
    57.2K followersView on X

Explore more