← Back

CVE-2026-3609

nvd nist
Published: May 11, 2026Modified: Aug 5, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.

Affected (1)

Products: Wellbia: Xigncode3
1 product
Xigncode3
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0.10011.16384

References (4)

Source: cret@cert.org
ExploitThird Party Advisory
Source: cret@cert.org
Broken Link
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.