Impact
The vulnerability exists in the MessageNotifyCallback function of ProtectFilter64.sys within Chengdu Qilu Technology’s Ludashi component. By manipulating the callback locally an attacker can bypass the built‑in authorization check, potentially granting elevated privileges or allowing unauthorized actions. This weakness is an authentication bypass identified as CWE‑862 and an improper access control flaw identified as CWE‑863.
Affected Systems
Affected software is Ludashi version 6.1026.4715.714 from Chengdu Qilu Technology. No other versions are listed, so only this exact build is known to be vulnerable.
Risk and Exploitability
The overall CVSS score of 4.6 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires local access, meaning an attacker must already have some degree of system presence. Publicly available exploit code has been released, which increases the likelihood that a local attacker is limited to attackers who can physically or otherwise locally access the system, the potential privilege escalation and arbitrary action capability justifies prompt remediation.
OpenCVE Enrichment