Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.
Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.
References
| Link | Resource |
|---|---|
| https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/ | Exploit Third Party Advisory |
| https://blacksnufkin.github.io/posts/Hunting-the-Hunter/ | |
| https://crcert.or.kr | Broken Link |
| https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-05-11 18:16
Updated : 2026-08-05 16:16
NVD link : CVE-2026-3609
Mitre link : CVE-2026-3609
CVE.ORG link : CVE-2026-3609
JSON object : View
Products Affected
wellbia
- xigncode3
CWE
