CyberRota Analysis
AI-GeneratedThe vulnerability exists in the IRP_MJ_WRITE command interface of Wellbia XIGNCODE3 xhunter2.sys, allowing local, unprivileged attackers to escalate privileges to NT AUTHORITY\SYSTEM. This can lead to the extraction of credentials from PPL-protected lsass.exe and the termination of critical security processes. Organizations using this software should prioritize patching to mitigate the risk of local privilege escalation attacks.
Original NVD Description
Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes.