CVE Explorer
CVE-2026-1880
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update.
Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory fo
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"DriverHub","vendor":"ASUS","versions":[{"lessThan":"1.0.6.12","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:70efac31446e35287a0f891ab6c26fae35609698d233a771ada731b27a9a4ccb · sha256:ae0a24932f134292… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":5.4,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImp…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:70efac31446e35287a0f891ab6c26fae35609698d233a771ada731b27a9a4ccb · sha256:ae0a24932f134292… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-367","description":"CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:70efac31446e35287a0f891ab6c26fae35609698d233a771ada731b27a9a4ccb · sha256:ae0a24932f134292… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.asus.com/security-advisory"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:70efac31446e35287a0f891ab6c26fae35609698d233a771ada731b27a9a4ccb · sha256:ae0a24932f134292… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.