CVE Explorer
CVE-2026-1878
An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is substituted with an unexpected payload immediately after download, resulting in arbitrary code execution. Refer to the "Security Update for ASUS ROG peripheral driver" section on the AS
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"Driver( Keyboard & Mouse )","vendor":"ASUS","versions":[{"lessThan":"1.0.66.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:46719f810a6aa32c087600e2be8c487ae558def8c2fce0aeb1825db6e06e7444 · sha256:7f6b57fe09b51caf… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"Driver( Headset )","vendor":"ASUS","versions":[{"lessThan":"1.0.12.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:46719f810a6aa32c087600e2be8c487ae558def8c2fce0aeb1825db6e06e7444 · sha256:7f6b57fe09b51caf… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"Driver( Keyboard & Mouse )","vendor":"ASUS","versions":[{"lessThan":"1.0.66.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:46719f810a6aa32c087600e2be8c487ae558def8c2fce0aeb1825db6e06e7444 · sha256:7f6b57fe09b51caf… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"Driver( Headset )","vendor":"ASUS","versions":[{"lessThan":"1.0.12.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:46719f810a6aa32c087600e2be8c487ae558def8c2fce0aeb1825db6e06e7444 · sha256:7f6b57fe09b51caf… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":5.4,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpa…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:46719f810a6aa32c087600e2be8c487ae558def8c2fce0aeb1825db6e06e7444 · sha256:7f6b57fe09b51caf… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-494","description":"CWE-494 Download of Code Without Integrity Check","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:46719f810a6aa32c087600e2be8c487ae558def8c2fce0aeb1825db6e06e7444 · sha256:7f6b57fe09b51caf… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.asus.com/security-advisory/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:46719f810a6aa32c087600e2be8c487ae558def8c2fce0aeb1825db6e06e7444 · sha256:7f6b57fe09b51caf… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.