CVE-2026-3609

Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cross reference to KVE 2023-5589 (https://krcert.or.kr)
Configurations

Configuration 1 (hide)

cpe:2.3:a:wellbia:xigncode3:10.0.10011.16384:*:*:*:*:*:*:*

History

13 May 2026, 14:17

Type Values Removed Values Added
First Time Wellbia xigncode3
Wellbia
References () https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/ - () https://blacksnufkin.github.io/posts/AntiCheat-LPE-CVE-2026-3609/ - Exploit, Third Party Advisory
References () https://crcert.or.kr - () https://crcert.or.kr - Broken Link
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:wellbia:xigncode3:10.0.10011.16384:*:*:*:*:*:*:*

11 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 18:16

Updated : 2026-05-13 14:17


NVD link : CVE-2026-3609

Mitre link : CVE-2026-3609

CVE.ORG link : CVE-2026-3609


JSON object : View

Products Affected

wellbia

  • xigncode3