THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-3609 (HIGH 7.8) — Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Note: KVE 2023-5589 (https://

[NVD] CVE-2026-3609 (HIGH 7.8) — Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Note: KVE 2023-5589 (https://

lownvdPublished 2026-05-11

CVE-2026-3609 CVSS: 7.8 HIGH Published: 2026-05-11T18:16:33.560

Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.

Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.100

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3609