An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update.
Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.asus.com/security-advisory |
Configurations
No configuration.
History
16 Apr 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-16 03:16
Updated : 2026-04-17 15:17
NVD link : CVE-2026-1880
Mitre link : CVE-2026-1880
CVE.ORG link : CVE-2026-1880
JSON object : View
Products Affected
No product.
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
