PT-2026-33244 · Asus · Driverhub

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-1880

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ASUS DriverHub (affected versions not specified)
Description An Incorrect Permission Assignment for Critical Resource in the update process allows privilege escalation. This occurs because required execution resources are not properly protected during the validation phase, enabling a local user to make unprivileged modifications. Consequently, the altered resource can bypass system checks and be executed with elevated privileges when a user initiates an update.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05566
CVE-2026-1880

Affected Products

Driverhub