CVE-2026-3609
5.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Summary
Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.
Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Wellbia | XIGNCODE3 | 10.0.10011.16384 <= 2023.12.7.78 | affected |
Weaknesses
- CWE-269 Improper Privilege Management
- CWE-732 Incorrect Permission Assignment for Critical Resource
- CWE-284 Improper Access Control
- CWE-266 Incorrect Privilege Assignment
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://crcert.or.kr
- https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/
- https://blacksnufkin.github.io/posts/Hunting-the-Hunter/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.