CVE-2026-3796 Details
Description
A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter Driver. Executing a manipulation can lead to improper access controls. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been identified in Qi-Anxin QAX Virus Removal versions prior to 2025-10-22. The issue resides in the Mini Filter Driver component, specifically within the QKSecureIO_Imp.sys library. The vulnerability arises from improper access controls in the ZwTerminateProcess function, allowing for arbitrary process termination. This weakness can be exploited locally by impersonating a legitimate caller process image, potentially targeting protected processes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cwjchoi01/FocusKiller | [email protected] | Product |
| https://github.com/cwjchoi01/FocusKiller/tree/main/FocusKiller | [email protected] | Product |
| https://vuldb.com/?ctiid.349763 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.349763 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.758991 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qianxin qax internet control gateway | <= 2025-10-22 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 10, 2026 | Initial Analysis | [email protected] |
| Mar 9, 2026 | New CVE Received | [email protected] |