THREAT OPS › Threat News › [NVD] CVE-2026-3609 (HIGH 7.8) — Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.
Note: KVE 2023-5589 (https://
[NVD] CVE-2026-3609 (HIGH 7.8) — Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Note: KVE 2023-5589 (https://
CVE-2026-3609 CVSS: 7.8 HIGH Published: 2026-05-11T18:16:33.560
Wellbia's XIGNCODE3 xhunter1.sys kernel driver, version 10.0.10011.16384 through 2023.12.7.78, privilege escalation vulnerability provides access to the IRP_MJ_WRITE command interface, which allows any user process to request a PROCESS_ALL_ACCESS.
Note: KVE 2023-5589 (https://krcert.or.kr) was initially issued for version 10.0.100
Indicators of compromise
- CVE-2026-3609cve
- https://krcert.or.krurl
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3609