CVE-2026-3609

Summary

Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.

Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.

Affected Software

VendorProductVersion RangeStatus
WellbiaXIGNCODE310.0.10011.16384 <= 2023.12.7.78affected

Weaknesses

  • CWE-269 Improper Privilege Management
  • CWE-732 Incorrect Permission Assignment for Critical Resource
  • CWE-284 Improper Access Control
  • CWE-266 Incorrect Privilege Assignment

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References