CVE-2026-3428
A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a Time-of-check Time-of-use (TOC-TOU) during the update process, where an unexpected payload is substituted for a legitimate one immediately after download, and subsequently executed with administrative privileges upon user consent. Refer to the 'Security Update for ASUS Member Center' section on the ASUS Security Advisory for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3428?
CVE-2026-3428 has been classified with a high severity level due to its potential impact on privilege escalation.
How do I fix CVE-2026-3428?
To fix CVE-2026-3428, update the ASUS Member Center software to the latest version provided by ASUS.
Who is affected by CVE-2026-3428?
Local users of ASUS Member Center are primarily affected by the vulnerability CVE-2026-3428.
What is the nature of the vulnerability in CVE-2026-3428?
CVE-2026-3428 is a Download of Code Without Integrity Check vulnerability that allows exploitation during the update process.
What can attackers achieve by exploiting CVE-2026-3428?
By exploiting CVE-2026-3428, attackers can achieve privilege escalation to Administrator level on affected systems.