High severity7.8NVD Advisory· Published May 11, 2026· Updated Aug 5, 2026
CVE-2026-3609
CVE-2026-3609
Description
Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.
Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/nvdExploitThird Party Advisory
- crcert.or.krnvdBroken Link
- blacksnufkin.github.io/posts/Hunting-the-Hunter/nvd
News mentions
0No linked articles in our index yet.