PT-2026-33244 · Asus · Driverhub
Published
2026-04-15
·
Updated
2026-04-16
·
CVE-2026-1880
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ASUS DriverHub (affected versions not specified)
Description
An Incorrect Permission Assignment for Critical Resource in the update process allows privilege escalation. This occurs because required execution resources are not properly protected during the validation phase, enabling a local user to make unprivileged modifications. Consequently, the altered resource can bypass system checks and be executed with elevated privileges when a user initiates an update.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Driverhub