Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-15430. PoCs published by BlackSnufkin.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-15430, a Local Privilege Escalation (LPE) vulnerability in the AxHunter driver (xhunter1.sys). The exploit bypasses Process Protection Light (PPL) to obtain a privileged process handle and inject shellcode into a target process, achieving SYSTEM-level command execution via WinExec.
Description
Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes.
Exploits (1)
This repository contains a functional exploit for CVE-2026-15430, a Local Privilege Escalation (LPE) vulnerability in the AxHunter driver (xhunter1.sys). The exploit bypasses Process Protection Light (PPL) to obtain a privileged process handle and inject shellcode into a target process, achieving SYSTEM-level command execution via WinExec.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N