216.73.217.22

CVE-2026-1878

· Published 12/03/2026 03:15 · Modified 12/03/2026 21:07

Labels: CVE-2026-1878 2026-03-1254bf65a7-a193-42d2-b1ba-8e150d3c35e1CVE-2026-1878CWE-494

Essential information

Published
12/03/2026 03:15
Modified
12/03/2026 21:07
Author
Creator
CVSS
5.4 MEDIUM (v3) 5.4 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is substituted with an unexpected payload immediately after download, resulting in arbitrary code execution. Refer to the "Security Update for ASUS ROG peripheral driver" section on the ASUS Security Advisory for more information.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
54bf65a7-a193-42d2-b1ba-8e150d3c35e1
NVD
View on NVD

Affected products (CPE)

ProductCPE
asus / rog peripheral driver cpe:2.3:a:asus:rog_peripheral_driver:*:*:*:*:*:*:*:*

References