SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15430

MEDIUM · CVSS 6.2 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The vulnerability exists in the IRP_MJ_WRITE command interface of Wellbia XIGNCODE3 xhunter2.sys, allowing local, unprivileged attackers to escalate privileges to NT AUTHORITY\SYSTEM. This can lead to the extraction of credentials from PPL-protected lsass.exe and the termination of critical security processes. Organizations using this software should prioritize patching to mitigate the risk of local privilege escalation attacks.

CVE
CVE-2026-15430
Severity
MEDIUM
CVSS
6.2
EPSS
0.20%

Original NVD Description

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes.