A local improper access control vulnerability exists in Qi-ANXIN QAX Virus Removal (up to 2025-10-22) within the Mini Filter Driver component, specifically in QKSecureIO_Imp.sys involving the ZwTerminateProcess call path. A local attacker can manipulate the vulnerable behavior to bypass intended access controls related to process termination, indicating insufficient authorization checks around the use of ZwTerminateProcess in the driver context. Public exploit code is reported to be available; vendor non-responsive to disclosure per the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Visual Studio C++ project implementing a Windows local privilege abuse/driver-communication exploit for CVE-2026-3796 in QAX Virus Removal. The project contains one meaningful source file, FocusKiller/FocusKiller/dllmain.cpp, plus standard solution/project metadata, headers, and a README. The code is built as a DLL, and the project name is set to 'UxTheme', while dllmain.cpp includes a long list of stubbed UxTheme exports. That strongly suggests the DLL is intended for sideloading/proxy-loading into a trusted process so the vulnerable driver will accept requests based on caller image identity. Core exploit behavior in dllmain.cpp includes: enabling SeLoadDriverPrivilege; creating/loading the vulnerable kernel minifilter service QKSecureIO_Imp; writing required service and minifilter instance registry keys under HKLM\SYSTEM\CurrentControlSet\Services\QKSecureIO_Imp; setting the minifilter altitude and default instance; calling FilterLoad to start the filter; and preparing a packed KILL_STRUCT containing a command code and target PID. Although the provided content is truncated, the README and visible code make clear the exploit then communicates with the vulnerable minifilter to request termination of an arbitrary process. The exploit is local, Windows-specific, and not a remote/network exploit. Its main capability is arbitrary process termination via a vulnerable driver that insufficiently validates both the caller identity and the target process. The README explicitly states this can be used against protected processes. The repository does not include the vulnerable driver itself, and the user must place QKSecureIO_Imp.sys in C:\Windows\system32\drivers and run with administrator rights. Overall, this is a real operational proof-of-concept exploit rather than a detector or fake sample.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.