What is CVE-2026-15430?
Improper access control in the IRP_MJ_WRITE command interface of Wellbia XIGNCODE3 xhunter2.sys driver. A local unprivileged attacker can achieve privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected processes. Affected version is 2026.6.1.192.
Azərbaycanca: Wellbia XIGNCODE3 xhunter2.sys sürücüsünün IRP_MJ_WRITE komanda interfeysində zəif giriş nəzarəti (improper access control) mövcuddur. Bu, yerli imtiyazsız hücumçuya NT AUTHORITY\SYSTEM səviyyəsinə yüksəlməyə, PPL ilə qorunan lsass.exe prosesindən etimadnamələri çıxarmağa imkan verir. Təsirə məruz qalan versiya 2026.6.1.192-dir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
In which interface of the Wellbia XIGNCODE3 xhunter2.sys driver was the improper access control vulnerability discovered?
The vulnerability was discovered in the IRP_MJ_WRITE command interface.
To which privileges can a local attacker escalate by exploiting this vulnerability?
A local unprivileged attacker can escalate to NT AUTHORITY\SYSTEM.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.