
Silverfox Group is actively exploiting CVE-2025-70795 in wild to terminate AV processes. Such driver is not in Windows vulnerable driver blocklist. The updated driver verify if the control code is from a SYSTEM Process, but still can be used. Reference: https://bbs.kafan.cn/thread-2288675-1-1.html https://t.co/04EJJa2xKR
Post summary
Silverfox Group is actively exploiting CVE‑2025‑70795 in the wild to terminate antivirus processes, and the driver is not on Microsoft’s blocklist.

