CVE-2026-90508 PUBLISHED

Chengdu Qilu Technology Ludashi Message Dispatch ProtectFilter64.sys MessageNotifyCallback authorization

Assigner: VulDB
Reserved: 12.09.2026 Published: 13.09.2026 Updated: 13.09.2026

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.6

Product Status

Vendor Chengdu Qilu Technology
Product Ludashi
Versions
  • Version 6.1026.4715.714 is affected

Credits

  • Bigcat (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Missing Authorization CWE
  • Incorrect Authorization CWE