Vulnerability Description
Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cross reference to KVE 2023-5589 (https://krcert.or.kr)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wellbia | Xigncode3 | 10.0.10011.16384 |
References
- https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/ExploitThird Party Advisory
- https://crcert.or.krBroken Link
- https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/ExploitThird Party Advisory
FAQ
What is CVE-2026-3609?
CVE-2026-3609 is a vulnerability with a CVSS score of 7.8 (HIGH). Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cro...
How severe is CVE-2026-3609?
CVE-2026-3609 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-3609?
Check the references section above for vendor advisories and patch information. Affected products include: Wellbia Xigncode3.