Description
Improper access control in the IRP_MJ_WRITE command interface in
Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to
NT AUTHORITY\SYSTEM, extract credentials from PPL-protected
lsass.exe, and terminate PPL-protected security processes.
Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to
NT AUTHORITY\SYSTEM, extract credentials from PPL-protected
lsass.exe, and terminate PPL-protected security processes.
Published:
2026-08-03
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://blacksnufkin.github.io/posts/Hunting-the-Hunter-II/ |
|
History
Mon, 03 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wellbia
Wellbia xigncode3 |
|
| Vendors & Products |
Wellbia
Wellbia xigncode3 |
Mon, 03 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes. | |
| Title | CVE-2026-15430 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-08-03T14:45:57.350Z
Reserved: 2026-07-10T17:06:29.447Z
Link: CVE-2026-15430
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T16:30:03Z
Weaknesses
No weakness.