Executive brief
The ASUS ROG peripheral driver installer contains an insufficient integrity verification vulnerability that allows attackers to exploit a race condition during the download process. By substituting the legitimate installer with malicious code immediately after download, an attacker can execute arbitrary code with SYSTEM privileges on affected machines. This could enable attackers to take complete control of a user's computer, install malware, or steal sensitive data.
Technical details
This vulnerability is a privilege escalation flaw stemming from improper access control on the installer download directory, combined with insufficient integrity verification of the installer binary. The attack exploits a race condition: after the legitimate installer is downloaded but before execution, an attacker with local or adjacent network access can substitute it with a malicious payload. The vulnerable component is the ASUS ROG peripheral driver installation process, which does not adequately verify the integrity of the downloaded installer or protect the directory from modification. Exploitation requires the victim to initiate a driver download, but no network authentication is required from the attacker's perspective. Successful exploitation results in arbitrary code execution with SYSTEM privileges. ASUS has indicated that a security update is available; users should apply the "Security Update for ASUS ROG peripheral driver" referenced in the ASUS Security Advisory.
Affected products
- ASUS ROG peripheral driver
Timeline
- 2026-03-12: disclosed