CVE-2026-108889 | Yungengxin Cloud Billing 2024.11.28.11 IOCTL Process Termination LWBilling64.sys sub_14000443C Pid exposed ioctl with insufficient access control
A vulnerability described as problematic has been identified in Yungengxin Cloud Billing 2024.11.28.11. Affected by this vulnerability is the function sub_14000443C in the library LWBilling64.sys of the component IOCTL Process Termination. Executing a manipulation of the argument Pid can lead to exposed ioctl with insufficient access control.
This vulnerability is registered as CVE-2026-108889. The attack needs to be launched locally. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More