CVE Explorer
CVE-2026-3428
A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a Time-of-check Time-of-use (TOC-TOU) during the update process, where an unexpected payload is substituted for a legitimate one immediately after download, and subsequently executed with administrative privileges upon user consent.
Refer to the 'Security Update for ASUS Member Center' section on the AS
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-367","description":"CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6bf91429b768c9d4c4ceb903855ccd7d5feb04d6238861a40dc341a0184b21a · sha256:24993214631f483c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-494","description":"CWE-494 Download of Code Without Integrity Check","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6bf91429b768c9d4c4ceb903855ccd7d5feb04d6238861a40dc341a0184b21a · sha256:24993214631f483c… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Member Center(华硕大厅)","vendor":"ASUS","versions":[{"status":"affected","version":"1.6.6.4 and earlier"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d6bf91429b768c9d4c4ceb903855ccd7d5feb04d6238861a40dc341a0184b21a · sha256:24993214631f483c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":5.4,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImp…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d6bf91429b768c9d4c4ceb903855ccd7d5feb04d6238861a40dc341a0184b21a · sha256:24993214631f483c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-367","description":"CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6bf91429b768c9d4c4ceb903855ccd7d5feb04d6238861a40dc341a0184b21a · sha256:24993214631f483c… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-494","description":"CWE-494 Download of Code Without Integrity Check","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6bf91429b768c9d4c4ceb903855ccd7d5feb04d6238861a40dc341a0184b21a · sha256:24993214631f483c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://www.asus.com/security-advisory/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6bf91429b768c9d4c4ceb903855ccd7d5feb04d6238861a40dc341a0184b21a · sha256:24993214631f483c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.