CVE-2026-3609

Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wellbia:xigncode3:10.0.10011.16384:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-11 18:16

Updated : 2026-08-05 16:16


NVD link : CVE-2026-3609

Mitre link : CVE-2026-3609

CVE.ORG link : CVE-2026-3609


JSON object : View

Products Affected

wellbia

  • xigncode3