Impact
The vulnerability arises from improper access control within the IRP_MJ_WRITE command interface of Wellbia XIGNCODE3's xhunter2.sys driver. A local, unprivileged user can issue write requests to the driver, triggering a bypass that elevates privileges to NT AUTHORITY\\SYSTEM. Once elevated, the attacker can read credentials from the protected LSASS process and terminate other protected security processes, effectively compromising system security and availability. This flaw exemplifies improper authorization, privilege escalation, and insecure permissions (CWE-269, CWE-284, CWE-732) and results in a complete loss of confidentiality, integrity, and availability for the affected system.
Affected Systems
Wellbia XIGNCODE3, xhunter2.sys version 2026.6.1.192. No other affected products are listed in the available data.
Risk and Exploitability
The exploit requires local access and an unprivileged account with write privileges to the driver files. The patch information is not disclosed, and the EPSS score is missing, making it unclear how frequently attackers may target an unpatched system. However, given the local nature of the attack and the ability to fully compromise the machine, the risk is high. The CVSS score is 6.2, indicating moderate severity. The CVE is not listed in CISA KEV, but the severity implied by the description warrants prompt remediation.
OpenCVE Enrichment