← volver
CVE-2026-1880

CVE-2026-1880

CVSS 5.4 MEDIUMEPSS 0.1%CWE-367
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.4EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
16 abr 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a local user to make unprivileged modifications. This allows the altered resource to pass system checks and be executed with elevated privileges upon a user-initiated update. Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
ASUS · DriverHub

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →