An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is substituted with an unexpected payload immediately after download, resulting in arbitrary code execution. Refer to the "Security Update for ASUS ROG peripheral driver" section on the ASUS Security Advisory for more information.
References
History

Thu, 12 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Description An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to improper access control on the installation directory, which enables the exploitation of a race condition where the legitimate installer is substituted with an unexpected payload immediately after download, resulting in arbitrary code execution. Refer to the "Security Update for ASUS ROG peripheral driver" section on the ASUS Security Advisory for more information.
First Time appeared Asus
Asus driver Headset
Asus driver Keyboard Mouse
Weaknesses CWE-494
CPEs cpe:2.3:a:asus:driver_headset_:*:*:*:*:*:*:*:*
cpe:2.3:a:asus:driver_keyboard_mouse_:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus driver Headset
Asus driver Keyboard Mouse
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ASUS

Published:

Updated: 2026-03-12T02:02:52.716Z

Reserved: 2026-02-04T07:15:59.413Z

Link: CVE-2026-1878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-12T03:15:57.570

Modified: 2026-03-12T03:15:57.570

Link: CVE-2026-1878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.