5.4
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update.
Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.
Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.
Basic Information
ID
CVE-2026-1880
Source
ASUS
Published
Apr 16, 2026 at 02:00
Modified
Apr 16, 2026 at 02:10
Affected Product
Vendor
ASUS
Product
DriverHub
Affected Versions
ASUS DriverHub 0