CVE-2026-90508
Received Received - Intake

Local Privilege Escalation in Ludashi ProtectFilter64.sys

Vulnerability report for CVE-2026-90508, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-13

Last updated on: 2026-09-13

Assigner: VulDB

Description

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-13
Last Modified
2026-09-13
Generated
2026-09-13
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
chengdu_qilu_technology ludashi 6.1026.4715.714

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a security flaw in Chengdu Qilu Technology Ludashi 6.1026.4715.714. It affects the function MessageNotifyCallback in the ProtectFilter64.sys library, specifically in the Message Dispatch Handler component. The issue allows for missing authorization when manipulated, requiring local access to exploit. A public exploit exists, and the vendor did not respond to early disclosure.

Detection Guidance

Detecting this vulnerability requires checking for the presence of the vulnerable ProtectFilter64.sys driver and monitoring for unusual process termination activity. Inspect system drivers for ProtectFilter64.sys and review logs for unexpected process kills, especially targeting Protected Process Light (PPL) processes.

Impact Analysis

An attacker with local access could exploit this to terminate processes, including Protected Process Light (PPL) processes, bypassing security protections. This could allow unauthorized system modifications or disruptions. The public availability of the exploit increases the risk of real-world attacks.

Compliance Impact

This vulnerability allows local attackers to bypass authorization and terminate protected processes via a kernel driver, which could lead to unauthorized system modifications or data access. Such capabilities may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) by enabling unauthorized access or tampering with protected systems.

Mitigation Strategies

Immediately remove or disable the Ludashi software and its associated ProtectFilter64.sys driver. Block unauthorized communication with the vulnerable driver's port. Monitor for any signs of exploitation and apply patches if the vendor releases updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90508. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart