CVE-2025-70795Active Exploitation

HIGHCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized processes to perform those actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications. Unauthorized processes load the driver and send a crafted IOCTL request (0xB822200C) to terminate processes protected by a third-party implementation. This action exploits insufficient caller validation in the driver's IOCTL handler, allowing unauthorized processes to perform termination operations in kernel space. Successful exploitation can lead to denial of service by disrupting critical third-party services or applications.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-14); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-14: 2Mentions · 2026-02-16: 1Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-02-14: 2Exploit Tool / Code · 2026-02-14: 1Active Exploitation · 2026-02-14: 1Technical Details · 2026-04-19: 102-1402-1604-19
Signal classification4 categories
Active Exploitation
125.0%
PoC
125.0%
General
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-142
Active Exploitation1PoC1
2026-02-161
General1
2026-04-191
Disclosure1
Full discourse4 posts
  • AnMioLink@anylink20240604
    Active Exploitation

    Silverfox Group is actively exploiting CVE-2025-70795 in wild to terminate AV processes. Such driver is not in Windows vulnerable driver blocklist. The updated driver verify if the control code is from a SYSTEM Process, but still can be used. Reference: https://bbs.kafan.cn/thread-2288675-1-1.html https://t.co/04EJJa2xKR

    Post summary

    Silverfox Group is actively exploiting CVE‑2025‑70795 in the wild to terminate antivirus processes, and the driver is not on Microsoft’s blocklist.

    657232717324.5K
    357 followersView on X
  • AnMioLink@anylink20240604
    PoC

    A PoC is published on https://github.com/ANYLNK/STProcessMonitorBYOVD/ #SilverFox #BYOVD #CVE #CVE-2025-70795

    Post summary

    A proof‑of‑concept for CVE‑2025‑70795 has been published on GitHub, providing a functional example of the exploit.

    0602782.5K
    357 followersView on X
  • AnMioLink@anylink20240604
    General

    Current vulnerability has two CVE IDs: CVE-2025-70795 and CVE-2026-0828. This post may update when the final ID come out.

    Post summary

    The post merely lists two CVE identifiers with no additional details or claims of exploitation, patches, or technical information.

    00010152
    357 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70795 STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are pro… https://www.cve.org/CVERecord?id=CVE-2025-70795

    Post summary

    The post discloses CVE‑2025‑70795, revealing that Safetica’s STProcessMonitor can be manipulated by privileged users to craft IOCTL requests that terminate processes. No PoC, exploit code, active exploitation, or patch information is provided.

    00000277
    57.2K followersView on X

Explore more