CVE-2026-3609 is a local privilege escalation vulnerability in Wellbia XIGNCODE3's xhunter1.sys kernel driver affecting version 10.0.10011.16384 through 2023.12.7.78. The driver exposes an IRP_MJ_WRITE command interface to unprivileged user-mode processes without sufficient access control, allowing a caller to request PROCESS_ALL_ACCESS handles to target processes. Because the vulnerable functionality is implemented in a kernel driver, improper authorization of this device interface enables a low-privileged process to invoke privileged operations that should be restricted by the operating system security model. The issue was previously addressed under KVE-2023-5589 for an earlier version, but the remediation was incomplete and the vulnerability remained present in version 2023.12.7.78.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Rust workspace containing two local Windows exploit PoCs plus a shared credential-extraction library. The repository targets Wellbia XIGNCODE3 anti-cheat drivers: axhunter_v1 attacks xhunter1.sys v2023.12.7.78, and axhunter_v2 attacks xhunter2.sys v2026.6.1.192 (CVE-2026-15430). The shared crate axhunter-lsa implements driver-agnostic LSASS secret extraction by abstracting memory reads behind a MemReader trait, then walking remote PEB/LDR structures, locating lsasrv.dll and wdigest.dll patterns, extracting BCrypt 3DES key material, and decrypting LogonSessionList and WDigest entries. Exploit capabilities are substantial and clearly offensive. Both variants first bypass driver-specific authorization gates, then use opcode 785 to obtain a kernel-minted PROCESS_ALL_ACCESS handle to arbitrary processes, including protected processes. They use opcode 787 as a cross-process memory read primitive for LSASS dumping, opcode 800 to forcibly close handles in a target process for process termination/evasion, and remote-thread injection into winlogon.exe for local privilege escalation to SYSTEM. The v1 exploit bypasses a per-PID gate by issuing unauthenticated commands 777 and 775 to set required flags. The v2 exploit is more complex: it bypasses three authentication layers by mapping an embedded signed WBMF module, crafting a minimal WBCC blob, and chaining commands 777, 779, and 775 to satisfy the PID flag gate. Repository structure: root workspace manifest; axhunter-lsa shared library; axhunter_v1 standalone PoC with driver wrapper, process helpers, and CLI; axhunter_v2 standalone PoC split into protocol, session, WBMF mapping, dump, kill, and LPE modules. Entry points are axhunter_v1/src/main.rs and axhunter_v2/src/main.rs. No network C2 or remote endpoints are present; this is a purely local Windows post-exploitation toolkit focused on abusing vulnerable anti-cheat drivers for credential theft, process tampering, and SYSTEM shell access.
This repository is a standalone Rust exploit/credential-dumping tool named CredsHunter. It is not part of a larger exploitation framework. The code targets CVE-2026-3609 in Wellbia's XIGNCODE3 anti-cheat driver xhunter1.sys and abuses the driver's write-based command interface to obtain a kernel-minted PROCESS_ALL_ACCESS handle to lsass.exe, bypassing Protected Process Light protections. Repository structure is compact and purpose-built: src/main.rs orchestrates execution and output; src/driver.rs implements the vulnerable driver protocol and session abstraction; src/proc.rs finds lsass.exe and walks the remote PEB/module list; src/pe.rs provides local PE parsing and pattern scanning; src/lsa.rs locates and extracts LSA cryptographic material and performs 3DES decryption; src/logon.rs walks LogonSessionList to recover NTLM and SHA1 hashes; src/wdigest.rs attempts plaintext password recovery from WDigest entries; src/sys.rs retrieves the Windows build number for selecting per-build signatures and offsets. Cargo.toml confirms a Windows-only Rust project using the windows crate. Main exploit capability: open the device \\.\xhunter, send a fixed-size WriteFile request with opcode 785, and receive a full-access process handle for an arbitrary PID. The code then targets lsass.exe specifically. If direct ReadProcessMemory works on the leaked handle, it uses that path; otherwise it falls back to opcode 787, which performs driver-side KeStackAttachProcess plus memcpy to read target memory. Post-exploitation capability is credential extraction rather than code execution. The tool loads local copies of lsasrv.dll and wdigest.dll, pattern-scans them to locate build-dependent globals/list heads, rebases those addresses into the remote LSASS mapping, extracts the live LSA 3DES key and IV from BCrypt structures, decrypts MSV1_0 credential blobs to print NTLM and SHA1 hashes, and then walks WDigest structures to try to recover plaintext passwords. The README and code both indicate support for multiple Windows builds via hardcoded signature tables, with WDigest support described as best-effort. No network communication or C2 behavior is present. The observable targets are local Windows device/file/module paths and driver opcodes. Overall, this is an operational local BYOVD credential dumper for Windows that chains a vulnerable signed anti-cheat driver into LSASS memory access and credential recovery.
This repository is a collection of operational Proof-of-Concept (PoC) exploits demonstrating the Bring Your Own Vulnerable Driver (BYOVD) technique to kill protected processes on Windows systems. Each subdirectory targets a specific vulnerable driver, with a Rust-based executable that loads the driver as a service, opens a device handle, and sends a crafted IOCTL to terminate a process by name or PID. The exploits require the vulnerable driver file to be present in the same directory as the executable and are designed for local execution with administrative privileges. The repository covers multiple drivers, including those from Baidu Antivirus (BdApiUtil64.sys, CVE-2024-51324), K7 Ultimate Security (K7RKScan.sys, CVE-2025-52915, CVE-2025-1055), ThreatFire System Monitor (sysmon.sys), Tg Soft (viragt64.sys), and Topaz Antifraud (wsftprm.sys, CVE-2023-52271). The main entry points are the Rust 'main.rs' files in each subdirectory. The exploits are not detection scripts but provide real process termination capability, which can be used to disable AV/EDR or other security software. The code is well-structured, modular, and leverages Windows service and device APIs to interact with the drivers. The attack vector is local, requiring administrative access to load the driver. The endpoints include the driver files and their respective device interfaces (e.g., \\.\BdApiUtil, \\.\ksapi64_dev, etc.). This collection is intended for research and educational purposes to demonstrate the risks of unprotected or vulnerable kernel drivers on Windows platforms.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.