Impact
The flaw resides in the xhunter1.sys kernel driver that ships with Wellbia XIGNCODE3. The driver exposes the IRP_MJ_WRITE IOCTL to any user‑space process, and an attacker can issue that control code to request PROCESS_ALL_ACCESS. If granted, the process receives full kernel privileges, bypassing normal isolation and enabling the execution of privileged actions. This is an access‑control weakness that allows a local user to elevate privileges to system level.
Affected Systems
Wellbia XIGNCODE3, specifically the xhunter1.sys driver, is affected. Versions ranging from 10.0.10011.16384 to 2023.12.7.78 contain the flaw. Earlier releases may also be vulnerable, but only the referenced range has confirmed evidence.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while the EPSS score of less than 1 % indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and the attack vector appears local: a malicious user process can drive the vulnerable IOCTL to obtain elevated privileges. A note from KRCERT shows that KVE 2023‑5589 was issued for version 10.0.10011.16384, but the issue remained in later builds, highlighting that remediation has not yet fully been applied.
OpenCVE Enrichment