{"id":"CVE-2026-1880","title":"An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …","summary":"An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …","severity":"medium","cvss":5.4,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-367"],"vendor":"ASUS","product":"DriverHub","affected":["DriverHub before 1.0.6.12"],"published":"2026-04-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T09:16:40.210","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-1880","references":[{"url":"https://www.asus.com/security-advisory","label":"54bf65a7-a193-42d2-b1ba-8e150d3c35e1"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.00139,"epssPercentile":0.03659,"exploits":{"github":1,"githubRepos":["https://github.com/seokjohn/CVE-2026-1880"],"checkedAt":"2026-09-21T15:28:16.881Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-04-16T12:22:14.841943Z"},"cvssSource":"cna","ingestedAt":"2026-09-17T09:14:58.450Z","slug":"CVE-2026-1880","body":"## Overview\n\nAn Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update.\nRefer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}