{"id":"CVE-2026-3609","title":"Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_A…","summary":"Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_A…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"wellbia","product":"xigncode3","affected":["xigncode3 = 10.0.10011.16384"],"published":"2026-05-11","updated":"2026-08-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-3609","references":[{"url":"https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/","label":"cret@cert.org"},{"url":"https://blacksnufkin.github.io/posts/Hunting-the-Hunter/","label":"cret@cert.org"},{"url":"https://crcert.or.kr","label":"cret@cert.org"},{"url":"https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.00232,"epssPercentile":0.14303,"ingestedAt":"2026-08-06T01:53:51.075Z","exploits":{"github":2,"githubRepos":["https://github.com/BlackSnufkin/BYOVD","https://github.com/BlackSnufkin/CredsHunter"],"checkedAt":"2026-09-23T07:14:02.199Z"},"exploitAvailable":true,"slug":"CVE-2026-3609","body":"## Overview\n\nWellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.\r\n\r\nNote: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.10011.16384, but the vulnerability was not fully remediated and remains in version 2023.12.7.78.\n\n## Affected\n\n- `xigncode3 = 10.0.10011.16384`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5138,"id":"CVE-2026-3609","ts":1788887250677,"field":"exploit_available","old":"false","new":"true"},{"seq":4021,"id":"CVE-2026-3609","ts":1788886366543,"field":"exploit_available","old":"true","new":"false"},{"seq":2832,"id":"CVE-2026-3609","ts":1788883033280,"field":"exploit_available","old":"false","new":"true"},{"seq":1861,"id":"CVE-2026-3609","ts":1788882436102,"field":"exploit_available","old":"true","new":"false"},{"seq":959,"id":"CVE-2026-3609","ts":1788881870056,"field":"exploit_available","old":"false","new":"true"}]}